Privacy Policy
Preamble
With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to as "data") that we process, for what purposes and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites, in mobile applications, and within external online presences, such as our social media profiles (hereinafter collectively referred to as "Online Offering").
The terms used are not gender-specific.
Last updated: September 24, 2026
Table of Contents
Controller
Marcel Plate
Berliner Str. 45
26127 Oldenburg
Email address: marcel@harie.coach
Overview of Processing Activities
The following overview summarizes the types of data processed and the purposes of their processing and refers to the data subjects.
Types of Data Processed
- Master data.
- Payment data.
- Contact data.
- Content data.
- Contract data.
- Usage data.
- Meta, communication and procedural data.
- Log data.
- Health data (e.g., heart rate and activity data from wearables, information on injuries, illness, pain, sleep and well-being).
- Image data (photos of workout descriptions for the Workout Capture feature).
Categories of Data Subjects
- Service recipients and clients.
- Prospective customers.
- Communication partners.
- Users.
- Business and contractual partners.
Purposes of Processing
- Provision of contractual services and fulfillment of contractual obligations.
- Communication.
- Security measures.
- Reach measurement.
- Organizational and administrative procedures.
- Feedback.
- AI-based training planning and evaluation.
- Automated training control.
- Profiles with user-related information.
- Provision of our online offering and user-friendliness.
- Information technology infrastructure.
- Public relations.
- Business processes and business management procedures.
Applicable Legal Bases
Applicable legal bases under the GDPR: The following provides an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or domicile. Should more specific legal bases be relevant in individual cases, we will inform you of these in the privacy policy.
- Consent (Art. 6(1)(a) GDPR) - The data subject has given consent to the processing of their personal data for one or more specific purposes.
- Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR) - Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
- Legal obligation (Art. 6(1)(c) GDPR) - Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6(1)(f) GDPR) - Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
National data protection regulations in Germany: In addition to the data protection regulations of the GDPR, national regulations on data protection apply in Germany. This includes in particular the Federal Data Protection Act (Bundesdatenschutzgesetz - BDSG). The BDSG contains specific provisions on the right to information, the right to deletion, the right to object, the processing of special categories of personal data, processing for other purposes, and the transmission and automated individual decision-making, including profiling. Furthermore, the data protection laws of the individual German federal states may also apply.
Security Measures
We take appropriate technical and organizational measures in accordance with legal requirements, taking into account the state of the art, the costs of implementation and the nature, scope, circumstances and purposes of processing, as well as the varying likelihood and severity of the threat to the rights and freedoms of natural persons, in order to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to data, as well as access, input, transmission, availability assurance and separation of data. Furthermore, we have established procedures that ensure the exercise of data subject rights, the deletion of data, and responses to data threats. We also take the protection of personal data into account from the outset in the development and selection of hardware, software and procedures, in accordance with the principle of data protection by design and by default.
Securing online connections through TLS/SSL encryption technology (HTTPS): To protect data transmitted via our online services from unauthorized access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the Internet. These technologies encrypt the information transmitted between the website or app and the user's browser (or between two servers), thereby protecting the data from unauthorized access. TLS is the more advanced and more secure successor to SSL. When a website is secured by an SSL/TLS certificate, this is indicated by the display of HTTPS in the URL. This serves as an indicator to users that their data is being transmitted securely and in encrypted form.
Transfer of Personal Data
In the course of our processing of personal data, it may happen that data is transferred to or disclosed to other entities, companies, legally independent organizational units or persons. Recipients of this data may include, for example, service providers entrusted with IT tasks or providers of services and content that are integrated into a website. In such cases, we comply with the legal requirements and in particular conclude appropriate contracts or agreements that serve to protect your data with the recipients of your data.
International Data Transfers
Data processing in third countries: If we transfer data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or if this occurs in the context of using third-party services or the disclosure or transfer of data to other persons, entities or companies (which is evident from the postal address of the respective provider or when the privacy policy explicitly refers to data transfers to third countries), this always takes place in compliance with legal requirements.
For data transfers to the USA, we rely, depending on the provider, either on the Data Privacy Framework (DPF), recognized as a safe legal framework by the adequacy decision of the EU Commission of July 10, 2023, or on Standard Contractual Clauses (SCC) of the EU Commission, which establish contractual obligations to protect your data. Which basis applies to a given service is stated with the respective service provider.
For the individual service providers, we inform you whether they are certified under the DPF and whether Standard Contractual Clauses are in place. Further information on the DPF and a list of certified companies can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/ (in English).
For data transfers to other third countries, corresponding safeguards apply, in particular Standard Contractual Clauses, explicit consent, or legally required transfers. Information on third-country transfers and applicable adequacy decisions can be found in the information provided by the EU Commission: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en.
General Information on Data Retention and Deletion
We delete personal data that we process in accordance with legal provisions as soon as the underlying consents are revoked or no further legal bases for processing exist. This applies to cases where the original processing purpose ceases to apply or the data is no longer needed. Exceptions to this rule exist where legal obligations or special interests require longer retention or archiving of the data.
In particular, data that must be retained for commercial or tax law reasons or whose storage is necessary for legal prosecution or for the protection of the rights of other natural or legal persons must be archived accordingly.
Our data protection notices contain additional information on the retention and deletion of data that apply specifically to certain processing operations.
Where there are multiple entries regarding the retention period or deletion deadlines for a datum, the longest period shall always prevail. Data that is no longer stored for its originally intended purpose but due to legal requirements or other reasons shall be processed exclusively for the reasons that justify its retention.
Data retention and deletion: The following general deadlines apply for retention and archiving under German law:
- 10 years - Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets and the working instructions and other organizational documents necessary for their understanding (Section 147(1) No. 1 in conjunction with Section 147(3) of the German Fiscal Code (AO), Section 14b(1) of the German VAT Act (UStG), Section 257(1) No. 1 in conjunction with Section 257(4) of the German Commercial Code (HGB)).
- 8 years - Accounting vouchers, such as invoices and cost receipts (Section 147(1) Nos. 4 and 4a in conjunction with Section 147(3) sentence 1 AO and Section 257(1) No. 4 in conjunction with Section 257(4) HGB).
- 6 years - Other business documents: received commercial or business letters, copies of dispatched commercial or business letters, other documents insofar as they are relevant for taxation purposes, e.g. hourly wage records, operating cost statements, calculation documents, price tags, but also payroll accounting documents insofar as they are not already accounting vouchers, and cash register receipts (Section 147(1) Nos. 2, 3, 5 in conjunction with Section 147(3) AO, Section 257(1) Nos. 2 and 3 in conjunction with Section 257(4) HGB).
- 3 years - Data required to take into account potential warranty and compensation claims or similar contractual claims and rights, as well as to process related inquiries, based on previous business experience and standard industry practices, shall be stored for the duration of the regular statutory limitation period of three years (Sections 195, 199 of the German Civil Code (BGB)).
Commencement of the period at the end of the year: If a period does not expressly begin on a specific date and is at least one year, it shall automatically commence at the end of the calendar year in which the event triggering the period occurred. In the case of ongoing contractual relationships in the context of which data is stored, the event triggering the period shall be the time at which the termination or other ending of the legal relationship takes effect.
Backups: Our server is fully backed up daily by our hosting provider (Hetzner Online GmbH, Germany); these backups are overwritten after seven days. In addition, we create backups of our database that are retained for up to 14 days. After a deletion (e.g. of your user account), the data may therefore remain in backup copies for up to 14 days. Backups are used exclusively for restoration in the event of a failure and are not evaluated for any other purpose.
Rights of Data Subjects
Rights of data subjects under the GDPR: As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Articles 15 to 21 GDPR:
- Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on those provisions. Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing; this also applies to profiling insofar as it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw any consent given at any time.
- Right of access: You have the right to obtain confirmation as to whether or not personal data concerning you is being processed, and to access such data, as well as further information and a copy of the data, in accordance with legal requirements.
- Right to rectification: In accordance with legal requirements, you have the right to request the completion of data concerning you or the rectification of inaccurate data concerning you.
- Right to erasure and restriction of processing: In accordance with legal requirements, you have the right to demand that data concerning you be deleted without undue delay, or alternatively, in accordance with legal requirements, to request restriction of the processing of the data.
- Right to data portability: You have the right to receive data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format in accordance with legal requirements, or to request its transmission to another controller.
- Complaint to a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement, if you consider that the processing of personal data relating to you infringes the GDPR.
Business Services
We process personal data of our contractual and business partners, such as customers, clients, prospective customers, suppliers and other cooperation partners (collectively referred to as "Contractual Partners"), for the purpose of initiating, executing and managing contractual relationships and comparable legal relationships. This also includes pre-contractual measures taken upon request, as well as communication in connection with the respective contractual relationship.
The processing serves in particular the fulfillment of our main and ancillary contractual obligations. These include the provision of agreed services, any update and information obligations, the handling of warranty and other performance disruptions, the processing of withdrawals, terminations of continuing obligations, reversals, refunds, as well as the processing of other contract-related declarations and inquiries. This covers both one-time contracts and ongoing contractual relationships.
In particular, master data such as name, address and, where applicable, company name, contact data such as email address and telephone number, contract and service data such as subject matter, term, order or reference number, usage and service data, payment and billing data, as well as communication content and histories are processed. Where necessary, we also process data that is disclosed or transmitted to us in the course of an assignment.
Furthermore, we process data for the protection of our rights and for the fulfillment of legal obligations. This includes, in particular, commercial and tax law retention obligations, documentation obligations, and, where applicable, verification and accountability obligations. In addition, processing takes place on the basis of our legitimate interests in proper business management, internal administration, risk management and IT security, as well as the protection of our business operations and our contractual partners against misuse, endangerment of data, secrets and other legal interests. This may also include the involvement of external service providers such as IT and telecommunications providers, payment service providers, banks, tax and legal advisors or other agents, insofar as this is necessary for the performance of the contract or the fulfillment of legal obligations.
The disclosure of personal data to third parties takes place exclusively insofar as this is necessary for the performance of the contract, the implementation of pre-contractual measures, the safeguarding of legitimate interests, or the fulfillment of legal obligations. We will separately inform you of any further processing, in particular for marketing purposes, within the scope of this privacy policy.
We inform the contractual partners of which data is required in each individual case in the context of data collection, for example in online forms through appropriate labeling or in personal contact.
The data is deleted as soon as it is no longer required for the aforementioned purposes and there are no legal retention obligations to the contrary. Legal retention periods, in particular under commercial and tax law, may require longer storage. Data transmitted in the course of a specific assignment will be deleted after completion of the assignment and expiry of any retention periods, provided there are no further legal or contractual obligations to store them.
The legal basis for processing is Art. 6(1)(b) GDPR for the implementation of pre-contractual measures and the fulfillment of the respective contractual relationship, as well as Art. 6(1)(c) GDPR for the fulfillment of legal obligations. Insofar as processing is based on legitimate interests, it takes place on the basis of Art. 6(1)(f) GDPR. Where the processing is based on Art. 6(1)(f) GDPR, it serves to protect our legitimate interests in proper and efficient business organization, internal administration and documentation of business transactions, the enforcement and defense of legal claims, the assurance of IT and data security, the prevention of misuse and fraud, and the economic management and development of our business operations. These interests exist in particular in ensuring secure and legally compliant business operations and in safeguarding our entrepreneurial capacity to act.
- Types of data processed: Master data (e.g. full name, residential address, contact information, customer number, etc.); Payment data (e.g. bank details, invoices, payment history); Contact data (e.g. postal and email addresses or telephone numbers); Contract data (e.g. subject matter, term, customer category); Usage data (e.g. page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and features). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Service recipients and clients; Prospective customers. Business and contractual partners.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfillment of contractual obligations; Security measures; Communication; Organizational and administrative procedures. Business processes and business management procedures.
- Retention and deletion: Deletion in accordance with the information in the section "General Information on Data Retention and Deletion".
- Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR); Legal obligation (Art. 6(1)(c) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).
Further notes on processing operations, procedures and services:
- Provision of software and platform services: We process the data of our users, registered users and any test users (hereinafter uniformly referred to as "Users") in order to provide our contractual services to them and on the basis of legitimate interests to ensure the security of our offering and to develop it further. The required information is identified as such in the context of the order, purchase or comparable contract conclusion and includes the information required for service provision and billing, as well as contact information to enable any necessary consultation; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR).
Import of HYROX race results: In HARIE you can enter the link to your personal results page on the official HYROX results platform. Our server then retrieves the publicly accessible results page and transfers your overall and station times to your account in order to determine your strengths and weaknesses. The operator of the results platform only receives our server's request for the address you provided; Service provider: mika:timing GmbH / race result AG (operator of results.hyrox.com); Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR).
Payment Procedures
In the context of contractual and other legal relationships, due to legal obligations or otherwise on the basis of our legitimate interests, we offer data subjects efficient and secure payment options and use the following service providers for this purpose (collectively "Payment Service Providers"): Stripe for subscriptions via the web app, and Apple and Google for subscriptions in the mobile app. Payment transactions are carried out exclusively via encrypted connections in accordance with the state of the art, so that the data entered is protected against unauthorized access during transmission.
The data processed by the payment service providers includes master data such as name, email address and, where applicable, billing address, payment data such as credit card numbers or bank details, as well as contract and amount information. This information is necessary to carry out the payments. Payment data is entered and stored exclusively with the payment service providers; we do not receive any account or credit card information, only information on the payment and subscription status. The data we exchange with each provider is described below under Stripe, Apple App Store/Google Play and RevenueCat.
The terms and conditions and privacy notices of the respective payment service providers apply to payment transactions and can be accessed within the respective websites or transaction applications. We also refer to these for further information and the exercise of rights of withdrawal, information and other data subject rights.
- Types of data processed: Master data (e.g. full name, residential address, contact information, customer number, etc.); Payment data (e.g. bank details, invoices, payment history); Contract data (e.g. subject matter, term, customer category); Usage data (e.g. page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and features). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Service recipients and clients; Business and contractual partners. Prospective customers.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfillment of contractual obligations. Business processes and business management procedures.
- Retention and deletion: Deletion in accordance with the information in the section "General Information on Data Retention and Deletion".
- Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).
Further notes on processing operations, procedures and services:
- Stripe (web subscriptions): Payment services for subscriptions purchased in the web app (app.harie.coach). Payment takes place on a checkout page hosted by Stripe (Stripe Checkout); payment details such as card numbers are entered and stored exclusively with Stripe, and we never receive payment instrument data. We transmit your e-mail address, your name, the selected subscription plan and a pseudonymous user ID to Stripe; from Stripe we receive a customer ID, the subscription status, the billing interval and the date of the next billing, which we store to activate and manage the subscription. We use Stripe in its "Managed Payments" model: the Stripe entity Sold through Link, LLC (USA) acts towards you as the merchant of record for the payment and handles the calculation and remittance of sales tax/VAT, invoicing, fraud prevention, dispute handling and customer support for payment matters; receipts, invoices and notices about trial and renewal are sent by Stripe/Link. For these purposes Stripe processes the data under its own responsibility. Stripe may offer you a Link account (link.com) to manage your subscription; in addition, we provide the Stripe customer portal so you can manage payment method, invoices and cancellation yourself. A deletion request submitted to Link results in cancellation of the subscription and deletion of the associated payment data at Stripe; Service provider: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland, as well as Stripe, Inc. and Sold through Link, LLC, 354 Oyster Point Blvd, South San Francisco, CA 94080, USA; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR); Legal obligation (Art. 6(1)(c) GDPR) regarding tax and commercial retention duties; Website: https://stripe.com; Privacy policy: https://stripe.com/privacy; Data processing agreement: part of the Stripe terms of service (https://stripe.com/legal/dpa). Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (SCC).
- Apple App Store and Google Play (in-app subscriptions): Subscriptions purchased in the mobile app are processed by the respective app store. Payment details are held exclusively by Apple or Google; we only receive a purchase confirmation and the subscription status. Management and cancellation take place in the subscription settings of the respective device; Service providers: Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland (privacy policy); Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (privacy policy); Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR).
- RevenueCat: Management and verification of in-app subscriptions of the mobile app (assignment of purchase receipts to user accounts, subscription status, renewal and expiration events). Processed data: a pseudonymous user ID, app store purchase receipts and subscription events; The RevenueCat SDK in the app is initially initialized with an anonymous identifier at app start, which is assigned to your account after you sign in. On iOS, the SDK also transmits the attribution token provided by Apple (AdServices) to RevenueCat so that we can recognize whether an installation originates from an Apple Search Ads campaign; the token is generated by Apple, contains no identifier of your person and does not enable tracking across other apps or websites. The transmission of the attribution token is based on our legitimate interest in measuring the success of our App Store advertising (Art. 6(1)(f) GDPR); the processing of the subscription data itself serves the performance of the contract. RevenueCat forwards subscription events under your pseudonymous identifier to our analytics tool PostHog (see section "Web Analytics, Monitoring and Optimization"); Service provider: RevenueCat, Inc., 633 Taraval St., Suite 101, San Francisco, CA 94116, USA; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR); Legitimate interests (Art. 6(1)(f) GDPR) for the attribution token; Website: https://www.revenuecat.com; Privacy policy: https://www.revenuecat.com/privacy. Basis for third-country transfers: Standard Contractual Clauses (SCC).
Provision of the Online Offering and Web Hosting
We process user data in order to provide our online services to them. For this purpose, we process the user's IP address, which is necessary to deliver the content and functions of our online services to the user's browser or device.
- Types of data processed: Usage data (e.g. page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and features); Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved); Log data (e.g. log files concerning logins or data retrieval or access times). Content data (e.g. textual or visual messages and posts, as well as information relating to them, such as details of authorship or time of creation).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online offering and user-friendliness; Information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)). Security measures.
- Retention and deletion: Deletion in accordance with the information in the section "General Information on Data Retention and Deletion".
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Further notes on processing operations, procedures and services:
- Provision of the online offering on rented storage space: For the provision of our online offering, we use storage space, computing capacity and software that we rent or otherwise obtain from a corresponding server provider (also known as "web host"); Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
- Collection of access data and log files: Access to our online offering is logged in the form of so-called "server log files." Server log files may include the address and name of the web pages and files accessed, date and time of access, data volumes transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. The server log files can be used for security purposes, e.g. to avoid server overload (especially in the case of abusive attacks, so-called DDoS attacks), and to ensure the utilization and stability of the servers; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR). Data deletion: Log file information is overwritten by automatic rotation and is generally not retained for longer than 30 days; as rotation depends on data volume, the actual period may differ in individual cases. Connection data is also processed by our network service provider Cloudflare (see below). Data whose further retention is required for evidentiary purposes is exempt from deletion until the respective incident has been finally resolved.
- Email sending and hosting: The web hosting services we use also include the sending, receiving and storage of emails. For these purposes, the addresses of recipients and senders, as well as further information relating to email dispatch (e.g. the providers involved) and the contents of the respective emails are processed. The aforementioned data may also be processed for the purpose of SPAM detection. We ask that you note that emails on the Internet are generally not sent encrypted. As a rule, emails are encrypted in transit, but (unless a so-called end-to-end encryption method is used) not on the servers from which they are sent and received. We can therefore accept no responsibility for the transmission path of emails between the sender and reception on our server; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
- Hetzner: Services in the field of providing information technology infrastructure and related services (e.g. storage space and/or computing capacities); Service provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.hetzner.com; Privacy policy: https://www.hetzner.com/legal/privacy-policy/. Data processing agreement: https://docs.hetzner.com/general/company-and-policy/data-protection-at-hetzner/.
- Cloudflare: Content delivery network (CDN), reverse proxy, DNS and protection against attacks (e.g. DDoS mitigation) for all domains of our online offering, i.e. the website, the web app and the programming interface used by the mobile app. All requests to our services are routed through Cloudflare's servers. Cloudflare processes the IP address, the requested address, browser or app identifiers and further connection data and decrypts the connection on its edge servers in order to inspect requests and forward them to our server; content is not stored permanently, only static files (e.g. images, scripts) are cached. Cloudflare retains connection data for security and operational purposes according to its own retention period; Service provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA; EU establishment: Cloudflare Germany GmbH, Rosental 7, 80331 Munich, Germany; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.cloudflare.com; Privacy policy: https://www.cloudflare.com/privacypolicy/; Data processing agreement: https://www.cloudflare.com/cloudflare-customer-dpa/. Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (SCC).
- Brevo (email delivery): Delivery of our transactional and notification emails (e.g. email address verification, password reset, subscription notices, confirmation of cancellations) via Brevo's SMTP service. Email address, name, message content and delivery metadata are processed. Brevo also receives automated DMARC reports on the delivery of emails from our domain; Service provider: Brevo (Sendinblue SAS), 7 rue de Madrid, 75008 Paris, France; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR); Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.brevo.com; Privacy policy: https://www.brevo.com/legal/privacypolicy/; Data processing agreement: part of the terms of use, https://www.brevo.com/legal/termsofuse/.
- Apple iCloud Mail (mailbox): The mailbox for the contact address stated in this privacy policy and in the legal notice is operated by Apple (iCloud Mail). Emails you send to us as well as internal notifications to us (e.g. about new registrations, cancellation requests or payment events, which may contain your email address and name) are stored there; Service provider: Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland; Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Privacy policy: https://www.apple.com/legal/privacy/en-ww/. Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (SCC).
Use of Cookies
The term "cookies" refers to functions that store information on users' devices and read information from them. Cookies can also be used in connection with various purposes, such as the functionality, security and convenience of online offerings, as well as the creation of analyses of visitor flows. We use cookies in accordance with legal requirements. To this end, we obtain the prior consent of users where required. If consent is not necessary, we rely on our legitimate interests. This applies where the storage and reading of information is essential to provide expressly requested content and functions. This includes, for example, the storage of settings as well as ensuring the functionality and security of our online offering. Consent can be revoked at any time. We provide clear information about its scope and which cookies are used.
Notes on data protection legal bases: Whether we process personal data using cookies depends on consent. If consent is given, it serves as the legal basis. Without consent, we rely on our legitimate interests, which are explained above in this section and in the context of the respective services and procedures.
Storage duration: With regard to storage duration, the following types of cookies are distinguished:
- Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user has left an online offering and closed their device (e.g. browser or mobile application).
- Permanent cookies: Permanent cookies remain stored even after the device is closed. For example, the login status can be saved and preferred content can be displayed directly when the user revisits a website. Similarly, user data collected with the help of cookies can be used for reach measurement. Unless we provide users with explicit information on the type and storage duration of cookies (e.g. when obtaining consent), they should assume that cookies are permanent and that the storage duration can be up to two years.
General information on revocation and objection (opt-out): Users can revoke the consent they have given at any time and also file an objection to processing in accordance with legal requirements, including via the privacy settings of their browser.
- Types of data processed: Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR). Consent (Art. 6(1)(a) GDPR).
Further notes on processing operations, procedures and services:
- Processing of cookie data on the basis of consent: On our website we use a cookie banner for this purpose. Without your consent, only strictly necessary cookies are set; analytics cookies (Google Analytics) are only set after you have consented to the "Analytics" category. Your choice is stored in the cookie "cc_cookie" (lifetime six months) and can be changed or withdrawn at any time via "Cookie settings" in the footer. The web app does not set analytics cookies. The mobile app does not use cookies; for usage analytics in the app (PostHog) we ask for separate consent on the first app start (see section "Web Analytics, Monitoring and Optimization"). We use a consent management solution in which the consent of users to the use of cookies or to the procedures and providers mentioned in the consent management solution is obtained. This procedure serves to obtain, log, manage and revoke consents, in particular with regard to the use of cookies and comparable technologies used to store, read and process information on users' devices. Within the scope of this procedure, the users' consents to the use of cookies and the associated processing of information, including the specific processing operations and providers mentioned in the consent management procedure, are obtained. Users also have the option of managing and revoking their consents. The consent declarations are stored in order to avoid repeated queries and to be able to provide evidence of consent in accordance with legal requirements. Storage takes place on the server side and/or in a cookie (so-called opt-in cookie) or by means of comparable technologies, in order to be able to assign consent to a specific user or their device. Unless there are specific details about the providers of consent management services, the following general notes apply: The duration of storage of consent is up to two years. A pseudonymous user identifier is created and stored together with the time of consent, the information on the scope of consent (e.g. relevant categories of cookies and/or service providers) and information about the browser, system and device used; Legal bases: Consent (Art. 6(1)(a) GDPR).
Blogs and Publication Media
We run a blog with editorial content on our website. The blog offers no comment or other interaction features. When reading, only the access data described in the section "Provision of the Online Offering and Web Hosting" is processed and – only with your consent – the analytics data described in the section "Web Analytics, Monitoring and Optimization".
- Types of data processed: Usage data (e.g. page views and dwell time, click paths); Meta, communication and procedural data (e.g. IP addresses, timestamps).
- Data subjects: Users (e.g. website visitors).
- Purposes of processing and legitimate interests: Provision of our online offering and user-friendliness.
- Retention and deletion: Deletion in accordance with the information in the section "General Information on Data Retention and Deletion".
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Registration, Login and User Account
Users can create a user account. During registration, users are informed of the required mandatory information and this is processed for the purpose of providing the user account on the basis of contractual obligation fulfillment. The data processed includes in particular login information (email address and password or, when signing in with Apple or Google, the provider identifier described below).
Registration is reserved for persons aged 18 and over. We do not knowingly collect personal data from minors; if we become aware that an account has been created by a minor, we delete it.
In the course of using our registration and login functions and using the user account, we store the IP address and the time of the respective user action. Storage takes place on the basis of our legitimate interests as well as those of the users in protection against misuse and other unauthorized use. This data is generally not disclosed to third parties unless it is necessary for the pursuit of our claims or there is a legal obligation to do so.
Users may be informed by email about events relevant to their user account, such as technical changes.
Logging of sign-in attempts: For security purposes we log successful and failed sign-in attempts on our servers. The data recorded includes the e-mail address used, the IP address, the user agent transmitted by the browser or app, the timestamp and, in case of a failure, the reason (e.g. wrong password, unverified e-mail address, deactivated account). These entries are stored in our server logs and are used solely to detect and prevent abuse (in particular brute-force attacks) and for forensic analysis of security incidents. The data is not disclosed to third parties. Retention is limited to what is necessary for these purposes (as a rule no more than 90 days), after which entries are overwritten during regular, volume-based log file rotation. Legal basis is Art. 6(1)(f) GDPR (legitimate interest in the security of our IT systems).
- Types of data processed: Master data (e.g. full name, residential address, contact information, customer number, etc.); Contact data (e.g. postal and email addresses or telephone numbers); Content data (e.g. textual or visual messages and posts, as well as information relating to them, such as details of authorship or time of creation); Usage data (e.g. page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and features). Log data (e.g. log files concerning logins or data retrieval or access times).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of contractual services and fulfillment of contractual obligations; Security measures; Organizational and administrative procedures. Provision of our online offering and user-friendliness.
- Retention and deletion: Deletion in accordance with the information in the section "General Information on Data Retention and Deletion". Deletion upon termination.
- Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).
Further notes on processing operations, procedures and services:
- User profiles are not public: User profiles are not publicly visible or accessible.
- Deletion of data upon termination: When users have terminated their user account, their data relating to the user account will be deleted, subject to any legal permission, obligation or consent of the users; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR).
- No obligation to retain data: It is the users' responsibility to back up their data before the end of the contract in the event of termination. We are entitled to irretrievably delete all data stored during the term of the contract; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR).
- Sign in with Apple and Google (single sign-on): As an alternative to e-mail registration, users can register and sign in with their Apple ID or Google account. After the user's approval, the respective provider transmits a signed sign-in token that we verify on our server; from it we receive the e-mail address (with Apple optionally an anonymised relay address), the name where provided, and a provider-specific user identifier that we store to link the user account. We never learn the password of the Apple or Google account. The providers learn through the sign-in that the user is signing in to HARIE; Service providers: Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland (privacy policy); Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (privacy policy); Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR). Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (SCC).
- Onboarding questionnaire (web app and mobile app): When registering, users answer questions about their training goal, training volume, health (e.g. injuries affecting training) and performance data before the account is created. Until the account is created these answers are stored solely locally in the user's browser or on the user's device and are transmitted to us only upon registration in order to set up the training profile and enable the first training plan by the AI coach (see section "AI-Based Training Planning and Evaluation"). Health information is processed on the basis of the explicit consent the user gives by voluntarily entering and submitting it (Art. 9(2)(a) GDPR); consent can be withdrawn at any time by deleting the information in the profile or the account.
- Push notifications (mobile app): With your permission in the operating system, HARIE sends push notifications, e.g. when a new training plan has been published or the evaluation of a session is available, as well as reminders for sessions and the daily health check. Delivery takes place via Expo's push service, which forwards the message to Apple's (APNs) or Google's (FCM) notification service. A device-specific push token as well as the title and text of the message, which may contain the title of the training session concerned, are transmitted. You can disable notifications at any time in the app settings or in the operating system; the push token is then deleted on our side; Service providers: Expo (650 Industries, Inc.), San Francisco, CA, USA; Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA; Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Legal bases: Consent (Art. 6(1)(a) GDPR); Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR); Privacy policy: https://expo.dev/privacy. Basis for third-country transfers: Standard Contractual Clauses (SCC); Apple and Google additionally Data Privacy Framework (DPF).
AI-Based Training Planning and Evaluation
HARIE's core feature is an AI coach ("HARIE AI-Coach") that creates training plans, evaluates completed training sessions and writes notes for athletes. For this we use large language models from the provider Anthropic, which we access via a programming interface (API). Plans, evaluations and notes labelled "by HARIE AI-Coach" in the app are generated by this AI and are not written by a human.
Which tasks the AI performs
- Weekly planning: Composing your training week (type, number and timing of sessions) and designing individual sessions (exercises, sets, intensities) – automatically every week, during onboarding and on request.
- Return-to-training planning: Creating an adapted plan after reported illness or injury.
- Session evaluation: Nightly assessment of completed key sessions (e.g. interval and threshold runs, HYROX sessions) with feedback and a recommendation for the next session.
- Notes: Weekly training briefings as well as welcome and information texts, e.g. when goals change.
- Plan corrections: Adjusting individual sessions when, for example, equipment is missing at the chosen location or the order of sessions has to be changed.
- Workout Capture (photo analysis): see below.
Which data is transmitted to the AI model
Depending on the task, excerpts of your training profile are transmitted to the AI model insofar as they are necessary for that task:
- Profile and performance data: sex, year of birth or age, height and weight (if provided), training level, weekly running volume, goals and competitions with dates, race results and splits, preferred training frequency and duration, availability times and the names of your training locations with the equipment available there.
- Training data: planned and completed sessions, your ratings (exertion/RPE, feeling), free-text comments and your "Feedback for HARIE" on individual sessions as well as – for evaluations – heart rate data (average, maximum, per-interval trend, time in heart rate zones) and your individual heart rate and pace zones.
- Health information: injury status and affected body regions, sick reports, restrictions (e.g. "currently cannot run"), your recovery status and – for the weekly note – your daily health checks (feeling, sleep rating from your manual entries – not from the wearable –, pain rating and areas, readiness to train, comment).
- Form of address: Your name is not transmitted to the AI model. HARIE inserts the personal salutation in notes only after the text has been generated.
Your email address, passwords, payment data and your account ID are not transmitted.
Health data
Information on injuries, illness, pain, sleep and well-being as well as heart rate data constitutes health data within the meaning of Art. 9(1) GDPR. We process it – including transmission to the AI model – exclusively on the basis of your explicit consent (Art. 9(2)(a) GDPR), which you give by voluntarily entering this information during onboarding, in the daily health check and when connecting a wearable. You can withdraw your consent at any time with effect for the future by deleting the information, disabling AI planning in the settings or deleting your account.
Workout Capture (photo analysis)
With the Workout Capture feature you can take a photo of a workout description (e.g. whiteboard, poster or screen) or select one from your gallery. The photo is transmitted to our server and from there to the AI model, which extracts the exercise structure. We do not store the photo; it is discarded after analysis. The processing of the photo by the AI provider, including retention there, is governed by the subsection "Service provider and third-country transfer". Please do not photograph people or third-party personal data. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).
Storage of AI outputs and logging
We store the plans, evaluations and notes created by the AI in your account so that you can view them; they are labelled as AI-generated. For each generation we log technical metrics (model used, time, volume, cost, validation result), but not the wording of the requests transmitted. The outputs are deleted together with your account.
Service provider and third-country transfer
We use the AI models via the Anthropic API. The contracting party and processor is Anthropic, PBC (USA); processing takes place in the USA. Anthropic does not use the transmitted data to train its models and deletes inputs and outputs within 30 days of processing. Content that Anthropic's automated safety systems classify as a violation of its usage policy may be retained by Anthropic for up to two years. Data processing is governed by a Data Processing Addendum that forms part of the Anthropic Commercial Terms; Anthropic's sub-processors are published in its list and changes are announced in advance.
- Types of data processed: Master data (sex, age); Health data (injuries, illness, pain, sleep, well-being, heart rate); Content data (training plans, comments, photos of workout descriptions); Usage data (training history, availability, locations); Meta, communication and procedural data (timestamps, model and cost metrics).
- Data subjects: Users.
- Purposes of processing: AI-based training planning and evaluation; Provision of contractual services and fulfillment of contractual obligations.
- Retention and deletion: Deletion together with the user account; deletion in accordance with the information in the section "General Information on Data Retention and Deletion".
- Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR); for health data consent (Art. 6(1)(a), Art. 9(2)(a) GDPR).
- Service provider: Anthropic, PBC, 548 Market St, PMB 90375, San Francisco, CA 94104, USA (EU establishment: Anthropic Ireland, Limited, 6th Floor, South Bank House, Barrow Street, Dublin 4, Ireland); Website: https://www.anthropic.com; Privacy policy: https://www.anthropic.com/privacy; Data processing agreement: https://www.anthropic.com/legal/data-processing-addendum (part of the Commercial Terms); Sub-processors: https://www.anthropic.com/subprocessors; Basis for third-country transfers: Standard Contractual Clauses (SCC).
No medical advice; deactivation: AI-generated plans and notes are algorithmically created recommendations and do not replace medical or physiotherapy advice. You can disable AI planning at any time in the settings (Training → AI planning) and plan your sessions manually; AI content already created remains until you delete it.
Automated Training Control
In addition to AI planning, HARIE contains rule-based automations that adjust your training plan without manual intervention. They concern training content only, have no legal effect and no similarly significant impact within the meaning of Art. 22 GDPR, and can be overridden by you at any time by creating, moving or deleting sessions manually or by disabling AI planning in the settings.
- Injury and illness status: If you report pain above a certain level or an illness in the daily health check, HARIE sets your profile to "injured" or "sick", records the affected body regions, suspends running in the case of leg or foot complaints and removes or regenerates affected AI-planned sessions. You see in advance which sessions are affected and confirm the adjustment.
- Load management: From your health checks of the last seven days (feeling, sleep, pain), HARIE detects signs of overload and then automatically applies a recovery measure – skipping the next sessions or a deload week. The status is shown to you and automatically reset once your values normalize.
- Evaluation of key sessions: The AI evaluation (see above) determines whether the next session of the same category is progressed, repeated or reduced.
- Types of data processed: Health data (health check entries); Usage data (training plan, training history).
- Data subjects: Users.
- Purposes of processing: Automated training control; safety and quality of training; provision of contractual services.
- Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR); for health information consent (Art. 9(2)(a) GDPR).
Wearable Integration and Health Data
HARIE offers the option to connect training data from Apple Health (iOS), Google Health Connect (Android) or exported activity files (FIT files, e.g. from Garmin devices) with your user account. This connection is entirely optional — HARIE can be used in full without any wearable integration.
Data Collected
When a connection is active, the HARIE app reads exclusively the following data types and transfers them to your HARIE account:
- Apple Health (iOS): workouts, heart rate, distance covered and active energy burned.
- Google Health Connect (Android): exercise sessions, heart rate and distance. GPS routes are – after separate approval in Health Connect – converted into distance values exclusively on your device; location coordinates never leave your device.
- FIT file import: From uploaded activity files, duration, distance, pace, heart rate trend, laps/intervals and, where available, power (watts) are extracted. The original file is additionally archived in our own, non-public object storage on our server.
Per session the following is transferred: start, duration, workout type, distance, pace, energy, average and maximum heart rate, the heart rate trend as a time series, detected segments and the name of the recording device or app (e.g. "Apple Watch" or "Garmin Connect"). Not read and not transferred are sleep data, heart rate variability (HRV), resting heart rate or any other health categories.
Special Category of Personal Data
Heart rate data constitutes health data pursuant to Art. 9(1) GDPR and is subject to special protection. The processing of this data is carried out exclusively on the basis of your explicit consent pursuant to Art. 9(2)(a) GDPR, which you provide by actively connecting in the app or uploading an activity file. You may withdraw this consent at any time with effect for the future by disconnecting the link in the app settings.
Purpose of Processing
- Automatic capture: Recorded activities are matched to your planned sessions so that you do not have to enter them manually.
- Evaluation by the AI coach: Heart rate and pace data of completed key sessions are transmitted to the AI model – as described in the section "AI-Based Training Planning and Evaluation" – in order to assess your session and adapt the next one.
- Training zones: From your heart rate data we derive individual heart rate and pace zones for training control.
Android: Google Health Connect
On Android devices, HARIE obtains workout data via Google Health Connect, the platform's native interface for aggregating health and fitness data. Access is granted only after you explicitly approve the individual data categories in the Health Connect permission dialog and can be revoked at any time.
Through Health Connect, HARIE accesses the following data types on a read-only basis and synchronizes them with your HARIE account: exercise sessions (workouts), heart rate, and distance. HARIE does not write any data back to Health Connect and does not access any other data categories stored there.
Data obtained via Health Connect is used solely for the training features described in this privacy policy (capturing, analyzing and optimizing your training, including the AI evaluation). It is not used for advertising purposes, not sold and only transmitted to the processors named in this privacy policy.
You can revoke the granted Health Connect permissions at any time — either directly in the Health Connect app or Android system settings, or by disconnecting the link in the HARIE app settings. When you disconnect in HARIE, the previously granted Health Connect read permissions are automatically revoked.
Data Sharing with Third Parties
Reading takes place via the Apple Health or Google Health Connect interfaces on your device; there is no connection to manufacturer services (e.g. Garmin Connect or Zepp). Your wearable data is transmitted to the following recipients: to Anthropic as processor for the AI evaluation (heart rate and pace values of completed sessions, see above), to our hosting provider Hetzner (storage) and, for technical reasons, to Cloudflare as network service provider (transmission path). No sharing for advertising purposes and no sale takes place.
Storage and Deletion
Synchronized wearable data is stored in a separate data area of your account in our database. You have the following deletion options:
- Separate deletion: You can delete your wearable data separately at any time in the app settings without affecting your user account.
- Account deletion: When you delete your user account, all wearable data including archived activity files is automatically and completely deleted as well.
- Disconnecting: By disconnecting the wearable link, no new data will be synchronized. Previously stored data will be retained until you explicitly delete it.
Security Measures
Due to the particular sensitivity of health data, we implement enhanced technical and organizational protective measures:
- Encrypted transmission of all wearable data (TLS/HTTPS).
- Storage in a separate data area, apart from account and payment data.
- Access to health data only after successful authentication.
- Types of data processed: Health data (heart rate); usage data (workout metrics, activity data, device name); content data (activity files).
- Data subjects: Users who voluntarily connect their wearable with HARIE or upload activity files.
- Purposes of processing: Automatic training capture; AI-based training evaluation; determination of training zones.
- Retention and deletion: Deletion upon user request (separately or upon account deletion). Deletion upon termination.
- Legal bases: Consent (Art. 6(1)(a), Art. 9(2)(a) GDPR). Performance of contract and pre-contractual inquiries (Art. 6(1)(b) GDPR).
Contact and Inquiry Management
When contacting us (e.g. by post, cancellation form, email, telephone or via social media) as well as in the context of existing user and business relationships, the information of the inquiring persons is processed insofar as this is necessary to respond to the contact inquiries and any requested measures.
- Types of data processed: Contact data (e.g. postal and email addresses or telephone numbers); Content data (e.g. textual or visual messages and posts, as well as information relating to them, such as details of authorship or time of creation). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Communication partners.
- Purposes of processing and legitimate interests: Communication; Organizational and administrative procedures; Feedback (e.g. collecting feedback via online form). Provision of our online offering and user-friendliness.
- Retention and deletion: Deletion in accordance with the information in the section "General Information on Data Retention and Deletion".
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR). Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR).
Further notes on processing operations, procedures and services:
- Contact by email: When contacting us by email or other communication channels, we process the personal data transmitted to us to respond to and process the respective inquiry. This usually includes information such as name, contact information and, where applicable, further information communicated to us and necessary for appropriate processing. Our mailbox is operated by Apple iCloud Mail (see section "Provision of the Online Offering and Web Hosting"). We use this data exclusively for the stated purpose of contact and communication; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR), Legitimate interests (Art. 6(1)(f) GDPR).
- Cancellation form (Section 312k German Civil Code): Via the cancellation page of our website you can cancel your subscription without logging in. Email address, name, the chosen payment method, an optional message and the time of receipt are processed. We confirm receipt by email and process the cancellation; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR); Legal obligation (Art. 6(1)(c) GDPR).
Web Analytics, Monitoring and Optimization
We analyze the use of our online offering in order to understand which content and features are used, at which points users abandon the signup or training process, and which areas we should improve. For this purpose we use two tools, which are described in detail below: Google Analytics on our website (only with your consent via the cookie banner) and PostHog for the mobile app and our server services. The web app (app.harie.coach) does not contain any analytics tool. We do not use A/B testing or session recordings, nor do we analyze location data or demographic characteristics.
Notes on legal bases: We only use Google Analytics and usage analytics via the PostHog SDK in the mobile app with your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). We process server-side events in PostHog on the basis of our legitimate interest (Art. 6(1)(f) GDPR). Details and options to withdraw consent or object can be found under the respective services.
- Types of data processed: Usage data (e.g. page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and features). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Reach measurement (e.g. access statistics, detection of returning visitors); Profiles with user-related information (creating user profiles). Provision of our online offering and user-friendliness.
- Retention and deletion: Deletion in accordance with the information in the section "General Information on Data Retention and Deletion". Google Analytics cookies on our website are stored for up to two years; the web app and the mobile app do not set analytics cookies.
- Legal bases: Consent (Art. 6(1)(a) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).
Further notes on processing operations, procedures and services:
- Google Analytics: Google Analytics is only loaded on our website if you have consented to the "Analytics" category in the cookie banner; without consent, no data is transmitted to Google. You can change or withdraw your consent at any time via "Cookie settings" in the footer; the analytics cookies set are then deleted. Advertising features (Google Signals, personalization) are disabled. We use Google Analytics to measure and analyze the use of our online offering on the basis of a pseudonymous user identification number. This identification number does not contain any unique data, such as names or email addresses. It is used to assign analytics information to a device in order to identify which content users have accessed within one or multiple usage sessions, which search terms they used, revisited, or interacted with our online offering. Likewise, the time of use and its duration are stored, as well as the sources of users referring to our online offering and technical aspects of their devices and browsers.
In this process, pseudonymous profiles of users are created with information from the use of different devices, whereby cookies may be used. Google Analytics does not log or store individual IP addresses for EU users. Analytics does, however, provide rough geographic location data by deriving the following metadata from IP addresses: city (and the derived latitude and longitude of the city), continent, country, region, subcontinent (and ID-based counterparts). For EU traffic, IP address data is used exclusively for this derivation of geolocation data before being immediately deleted. It is not logged, is not accessible, and is not used for any further purposes. When Google Analytics collects measurement data, all IP queries are performed on EU-based servers before the traffic is forwarded to Analytics servers for processing; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1)(a) GDPR); Website: https://marketingplatform.google.com/about/analytics/; Security measures: IP masking (pseudonymization of the IP address); Privacy policy: https://policies.google.com/privacy; Data processing agreement: https://business.safety.google/adsprocessorterms/; Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (https://business.safety.google/adsprocessorterms); Opt-out option: Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=en, Settings for the display of advertisements: https://myadcenter.google.com/personalizationoff. Further information: https://business.safety.google/adsservices/ (types of processing and data processed). - PostHog: We use PostHog to analyze the use of our mobile app and our server services (product analytics). No PostHog SDK is embedded in the web app; actions in the web app are only reflected through the server-side events described below. After login, events are assigned to a pseudonymous user identifier (internal account ID), supplemented by platform, language and subscription tier, so that we can perform funnel and usage analyses across the entire signup and training process. Clear data such as name or email address is not transmitted, nor are training content, health values or photos. However, individual events contain metadata such as the type of a session or the trigger of a plan adjustment (e.g. "injury" or "recovery"), which indicates that a health check led to an adjustment. Session recordings (session replay) are disabled. Processing takes place exclusively on servers within the European Union (PostHog Cloud EU, Frankfurt am Main region). We distinguish two types of collection:
a) Usage analytics in the mobile app (PostHog SDK): The PostHog SDK is only activated after you have consented to usage analytics on the first app start; without consent, no analytics data is sent from the app to PostHog. After consent, the SDK records app start and lifecycle events, screens viewed (without content) and usage events such as start of registration, completed onboarding steps, opening the training plan, viewing and completing sessions, connecting a wearable, importing an activity file, tapping hints about the web app and viewing the payment screen. The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). You can withdraw your consent at any time with effect for the future in the app under Profile → Settings → Privacy; the lawfulness of processing carried out before the withdrawal remains unaffected.
b) Server-side events: Regardless of your choice in the app, our server services record registration, email verification, creation and adaptation of training plans, generated evaluations and subscription events; in addition, our subscription service provider RevenueCat transmits subscription events (e.g. start or end of a trial) to PostHog under the same pseudonymous user identifier. This does not involve access to your device. The legal basis is our legitimate interest in analyzing and improving our service and in measuring the success of our signup and subscription processes (Art. 6(1)(f) GDPR). You can object to this processing at any time informally by email to the contact address given above;
Service provider: PostHog, Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA (data hosting: PostHog Cloud EU, Frankfurt am Main, Germany); Legal bases: Consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG) for usage analytics in the mobile app; Legitimate interests (Art. 6(1)(f) GDPR) for server-side events; Website: https://posthog.com; Privacy policy: https://posthog.com/privacy; Data processing agreement: https://posthog.com/dpa; Opt-out option: Mobile app: withdraw consent under Profile → Settings → Privacy; server-side events: informal objection by email to the contact address given above. Basis for third-country transfers: Data hosting within the EU; insofar as the provider exceptionally accesses data from the USA: Standard Contractual Clauses.
Presences in Social Networks (Social Media)
We maintain online presences within social networks and process user data in this context in order to communicate with users active there or to offer information about us.
We point out that user data may be processed outside the European Union. This may give rise to risks for users, as it could, for example, make it more difficult to enforce user rights.
Furthermore, user data within social networks is typically processed for market research and advertising purposes. For example, usage profiles can be created based on usage behavior and the resulting interests of users. These may in turn be used, for example, to place advertisements within and outside the networks that presumably correspond to the users' interests. For these purposes, cookies are generally stored on users' devices, in which the usage behavior and interests of users are stored. Furthermore, data independent of the devices used by the users may also be stored in the usage profiles (in particular if the users are members of the respective platforms and are logged in to them).
For a detailed description of the respective processing operations and the opt-out options, we refer to the privacy policies and information provided by the operators of the respective networks.
Also in the case of requests for information and the assertion of data subject rights, we point out that these can be most effectively asserted with the providers. Only the latter have access to the user data and can directly take appropriate measures and provide information. Should you nevertheless need assistance, you can contact us.
- Types of data processed: Contact data (e.g. postal and email addresses or telephone numbers); Content data (e.g. textual or visual messages and posts, as well as information relating to them, such as details of authorship or time of creation). Usage data (e.g. page views and dwell time, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and features).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Communication; Feedback (e.g. collecting feedback via online form). Public relations.
- Retention and deletion: Deletion in accordance with the information in the section "General Information on Data Retention and Deletion".
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Further notes on processing operations, procedures and services:
- Instagram: Social network, enables the sharing of photos and videos, commenting on and favoriting posts, messaging, subscribing to profiles and pages; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.instagram.com; Privacy policy: https://privacycenter.instagram.com/policy/. Basis for third-country transfers: Data Privacy Framework (DPF).
Plugins and Embedded Functions and Content
We only integrate the functional elements listed below into our online offering. We serve fonts from our own server. Only for signing in with Google or Apple in the web app are scripts loaded from these providers' servers; for technical reasons they receive your IP address and technical browser data.
- Types of data processed: Meta, communication and procedural data (e.g. IP addresses, timestamps, browser and device information).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online offering and user-friendliness.
- Retention and deletion: Deletion in accordance with the information in the section "General Information on Data Retention and Deletion".
- Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).
Further notes on processing operations, procedures and services:
- Google Fonts (hosted on own server): Provision of font files for a user-friendly display of our online offering; Service provider: Google Fonts are hosted on our server, no data is transmitted to Google; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
- Google Identity Services and Sign in with Apple (sign-in scripts in the web app): For signing in with Google or Apple in the web app, the providers' sign-in scripts are loaded from their servers (accounts.google.com, appleid.cdn-apple.com). The providers thereby receive your IP address and technical browser data; the actual sign-in only takes place after you click the respective button (see section "Registration, Login and User Account"); Service providers: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR); Legitimate interests (Art. 6(1)(f) GDPR). Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (SCC).
Amendments and Updates
We ask you to regularly inform yourself about the content of our privacy policy. We adapt the privacy policy as soon as changes in the data processing carried out by us make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or other individual notification.
Where we provide addresses and contact information of companies and organizations in this privacy policy, please note that addresses may change over time and please check the information before contacting us.
Definitions
In this section you will find an overview of the terms used in this privacy policy. Insofar as the terms are legally defined, their legal definitions apply. The following explanations are primarily intended to aid understanding.
- Master data: Master data includes essential information necessary for the identification and management of contractual partners, user accounts, profiles and similar allocations. This data may include, among other things, personal and demographic information such as names, contact information (addresses, telephone numbers, email addresses), dates of birth and specific identifiers (user IDs). Master data forms the basis for any formal interaction between persons and services, facilities or systems by enabling unique allocation and communication.
- Content data: Content data includes information generated in the course of creating, editing and publishing content of all kinds. This category of data may include texts, images, videos, audio files and other multimedia content published on various platforms and media. Content data is not limited to the actual content but also includes metadata that provides information about the content itself, such as tags, descriptions, author information and publication dates.
- Contact data: Contact data is essential information that enables communication with persons or organizations. It includes, among other things, telephone numbers, postal addresses and email addresses, as well as communication means such as social media handles and instant messaging identifiers.
- Meta, communication and procedural data: Meta, communication and procedural data are categories that contain information about the way in which data is processed, transmitted and managed. Meta data, also known as data about data, includes information that describes the context, origin and structure of other data. It may include information about file size, creation date, author of a document and change histories. Communication data captures the exchange of information between users via various channels, such as email traffic, call logs, messages in social networks and chat histories, including the persons involved, timestamps and transmission paths. Procedural data describes the processes and workflows within systems or organizations, including workflow documentation, logs of transactions and activities, and audit logs used for tracking and reviewing operations.
- Usage data: Usage data refers to information that captures how users interact with digital products, services or platforms. This data encompasses a wide range of information showing how users use applications, which features they prefer, how long they spend on certain pages and through which paths they navigate through an application. Usage data may also include frequency of use, timestamps of activities, IP addresses, device information and location data. It is particularly valuable for analyzing user behavior, optimizing user experiences, personalizing content and improving products or services. Furthermore, usage data plays a crucial role in identifying trends, preferences and potential problem areas within digital offerings.
- Personal data: "Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- Profiles with user-related information: The processing of "profiles with user-related information," or "profiles" for short, includes any type of automated processing of personal data that consists of using such personal data to analyze, evaluate or predict certain personal aspects relating to a natural person (depending on the type of profiling, this may include different information concerning demographics, behavior and interests, such as interaction with websites and their content, etc.) (e.g. interests in certain content or products, click behavior on a website or location). Cookies and web beacons are frequently used for profiling purposes.
- Log data: Log data is information about events or activities that have been logged in a system or network. This data typically contains information such as timestamps, IP addresses, user actions, error messages and other details about the use or operation of a system. Log data is often used for system problem analysis, security monitoring or performance reporting.
- Reach measurement: Reach measurement (also referred to as web analytics) is used to evaluate visitor flows of an online offering and may include the behavior or interests of visitors in certain information, such as website content. With the help of reach analysis, operators of online offerings can, for example, identify at which times users visit their websites and which content they are interested in. This enables them, for example, to better adapt the content of their websites to the needs of their visitors. Pseudonymous cookies and web beacons are frequently used for the purposes of reach analysis in order to recognize returning visitors and thus obtain more precise analyses of the use of an online offering.
- Controller: The "controller" is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: "Processing" means any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data, be it collection, evaluation, storage, transmission or deletion.
- Contract data: Contract data is specific information relating to the formalization of an agreement between two or more parties. It documents the conditions under which services or products are provided, exchanged or sold. This data category is essential for the management and fulfillment of contractual obligations and includes both the identification of the contracting parties and the specific terms and conditions of the agreement. Contract data may include start and end dates of the contract, the type of agreed services or products, pricing agreements, payment terms, termination rights, renewal options and special conditions or clauses. It serves as the legal basis for the relationship between the parties and is crucial for clarifying rights and obligations, enforcing claims and resolving disputes.
- Payment data: Payment data includes all information required for the processing of payment transactions between buyers and sellers. This data is of critical importance for electronic commerce, online banking and any other form of financial transaction. It includes details such as credit card numbers, bank account details, payment amounts, transaction data, verification numbers and billing information. Payment data may also include information about payment status, chargebacks, authorizations and fees.
Created with the free Datenschutz-Generator.de by Dr. Thomas Schwenke