This English version applies to visitors and clients who use this website in English. A German version is available at thomasdippold.com/datenschutzerklaerung/. Both versions have the same content.
1. Privacy at a glance
General information
The following notes give a simple overview of what happens to your personal data when you visit this website. Personal data is any data by which you can be personally identified. For detailed information on data protection, please see the privacy policy set out below this text.
Data collection on this website
Who is responsible for collecting data on this website?
Data processing on this website is carried out by the website operator. You can find the operator’s contact details in the section „Information on the controller“ in this privacy policy.
How do we collect your data?
Your data is collected in part because you provide it to us. This may be data that you enter into a contact form, for example.
Other data is collected automatically or with your consent by our IT systems when you visit the website. This is primarily technical data (for example internet browser, operating system or the time the page was accessed). This data is collected automatically as soon as you enter this website.
What do we use your data for?
Part of the data is collected to ensure that the website is provided without errors. Where contracts can be concluded or initiated through the website, the data submitted is also processed for contract offers, orders or other order enquiries.
What rights do you have regarding your data?
You have the right at any time to receive information free of charge about the origin, recipients and purpose of your stored personal data. You also have a right to request that this data be corrected or deleted. If you have given consent to data processing, you can withdraw that consent at any time with effect for the future. You also have the right, under certain circumstances, to request that the processing of your personal data be restricted. You also have a right to lodge a complaint with the competent supervisory authority.
You can contact us at any time about this and about any other questions on the subject of data protection.
2. Hosting
We host the content of our website with the following provider:
IONOS
The provider is IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany („IONOS“). When you visit our website, IONOS records various log files including your IP addresses. For details please see the IONOS privacy policy: ionos.de/terms-gtc/terms-privacy.
IONOS is used on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in presenting our website as reliably as possible. Where a corresponding consent has been requested, processing takes place exclusively on the basis of Art. 6(1)(a) GDPR and § 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user’s device (for example device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.
Data processing agreement
We have concluded a data processing agreement for the use of the service named above. This is a contract required by data protection law which ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
3. General information and mandatory disclosures
Data protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection provisions and this privacy policy.
When you use this website, various items of personal data are collected. Personal data is data by which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this happens.
We point out that data transmission over the internet (for example when communicating by email) can have security gaps. Complete protection of data against access by third parties is not possible.
Information on the controller
The controller for data processing on this website is:
Thomas Dippold
Gabelsbergerstraße 40
80333 Munich
Germany
Email: mail@thomasdippold.com
The controller is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data (for example names, email addresses and the like).
Storage period
Unless a more specific storage period is stated within this privacy policy, your personal data remains with us until the purpose for the data processing no longer applies. If you make a justified request for deletion or withdraw consent to data processing, your data will be deleted unless we have other legally permissible grounds for storing your personal data (for example retention periods under tax or commercial law); in the latter case, deletion takes place once those grounds no longer apply.
General information on the legal bases for data processing on this website
If you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR where special categories of data under Art. 9(1) GDPR are processed. In the case of express consent to the transfer of personal data to third countries, data processing also takes place on the basis of Art. 49(1)(a) GDPR. If you have consented to the storage of cookies or to access to information on your device (for example via device fingerprinting), data processing additionally takes place on the basis of § 25(1) TDDDG. Consent can be withdrawn at any time. Where your data is necessary for the performance of a contract or for taking steps prior to entering into a contract, we process your data on the basis of Art. 6(1)(b) GDPR. Furthermore, we process your data where it is necessary for compliance with a legal obligation, on the basis of Art. 6(1)(c) GDPR. Data processing may also take place on the basis of our legitimate interest under Art. 6(1)(f) GDPR. The legal bases relevant in each individual case are set out in the following paragraphs of this privacy policy.
Recipients of personal data
In the course of our business activities we work with various external parties. In some cases this also requires the transfer of personal data to those external parties. We only pass personal data to external parties where this is necessary for the performance of a contract, where we are legally obliged to do so (for example passing data to tax authorities), where we have a legitimate interest under Art. 6(1)(f) GDPR in passing it on, or where some other legal basis permits the transfer. Where we use processors, we pass on our clients’ personal data only on the basis of a valid data processing agreement. In the case of joint processing, a joint processing agreement is concluded.
Withdrawal of your consent to data processing
Many data processing operations are only possible with your express consent. You can withdraw consent you have already given at any time. The lawfulness of the data processing carried out up to the point of withdrawal is unaffected by the withdrawal.
Right to object to the collection of data in special cases and to direct marketing (Art. 21 GDPR)
IF DATA PROCESSING TAKES PLACE ON THE BASIS OF ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA ON GROUNDS ARISING FROM YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS THE PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (OBJECTION UNDER ART. 21(1) GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH MARKETING; THIS ALSO APPLIES TO PROFILING INSOFAR AS IT IS CONNECTED WITH SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR THE PURPOSE OF DIRECT MARKETING (OBJECTION UNDER ART. 21(2) GDPR).
Right to lodge a complaint with the competent supervisory authority
In the event of infringements of the GDPR, data subjects have a right to lodge a complaint with a supervisory authority, in particular in the member state of their habitual residence, their place of work or the place of the alleged infringement. This right to complain applies without prejudice to any other administrative or judicial remedy.
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only take place insofar as it is technically feasible.
Information, correction and deletion
Within the scope of the applicable statutory provisions, you have the right at any time to free information about your stored personal data, its origin and recipients and the purpose of the data processing and, where applicable, a right to have this data corrected or deleted. You can contact us at any time about this and about any further questions on the subject of personal data.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. You can contact us about this at any time. The right to restriction of processing exists in the following cases:
- If you dispute the accuracy of your personal data stored with us, we usually need time to check this. For the duration of the check you have the right to request the restriction of the processing of your personal data.
- If the processing of your personal data was or is unlawful, you can request the restriction of data processing instead of deletion.
- If we no longer need your personal data but you need it to exercise, defend or establish legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion.
- If you have lodged an objection under Art. 21(1) GDPR, a balancing of your interests and ours must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, this data may, apart from being stored, only be processed with your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of an important public interest of the European Union or of a member state.
SSL and TLS encryption
For security reasons and to protect the transmission of confidential content, such as orders or enquiries that you send to us as the site operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the browser address line changes from http:// to https:// and by the lock symbol in your browser line.
When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Objection to advertising emails
The use of contact data published under the obligation to provide an imprint for the purpose of sending unsolicited advertising and information material is hereby prohibited. The operators of the pages expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, for example by spam emails.
4. Data collection on this website and in the course of the coaching
Cookies
Our web pages use so-called cookies. Cookies are small data packets and do no harm to your device. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (permanent cookies). Session cookies are deleted automatically at the end of your visit. Permanent cookies remain stored on your device until you delete them yourself or until they are deleted automatically by your web browser.
Cookies can come from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies make it possible to integrate certain services of third-party companies within web pages (for example cookies for handling payment services).
Cookies have various functions. Many cookies are technically necessary because certain website functions would not work without them (for example the shopping cart function or the display of videos). Other cookies can be used to evaluate user behavior or for advertising purposes.
Cookies that are necessary to carry out the electronic communication process, to provide certain functions you have requested (for example the shopping cart function) or to optimize the website (for example cookies for measuring the web audience) (necessary cookies) are stored on the basis of Art. 6(1)(f) GDPR unless another legal basis is stated. The website operator has a legitimate interest in storing necessary cookies for the technically error-free and optimized provision of its services. Where consent to the storage of cookies and comparable recognition technologies has been requested, processing takes place exclusively on the basis of that consent (Art. 6(1)(a) GDPR and § 25(1) TDDDG); consent can be withdrawn at any time.
You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when the browser is closed. If cookies are deactivated, the functionality of this website may be limited.
Where further cookies and services are used on this website, you can find this out in this privacy policy.
Server log files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- browser type and browser version
- operating system used
- referrer URL
- host name of the accessing computer
- time of the server request
- IP address
This data is not merged with other data sources.
This data is collected on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and the optimization of its website, and server log files must be recorded for this purpose.
Google Fonts (local hosting)
This site uses so-called Google Fonts, provided by Google, for the consistent display of fonts. The Google Fonts are installed locally. No connection to Google servers takes place in the process.
For more information on Google Fonts see developers.google.com/fonts/faq and the Google privacy policy: policies.google.com/privacy.
Enquiry by email, telephone or fax
If you contact us by email, telephone or fax, your enquiry including all personal data arising from it (name, enquiry) is stored and processed by us for the purpose of handling your request. We do not pass this data on without your consent.
This data is processed on the basis of Art. 6(1)(b) GDPR where your enquiry is connected with the performance of a contract or is necessary for taking steps prior to entering into a contract. In all other cases, processing is based on our legitimate interest in the effective handling of enquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) where this has been requested; consent can be withdrawn at any time.
The data you send us via contact enquiries remains with us until you ask us to delete it, withdraw your consent to storage, or the purpose for storing the data no longer applies (for example once your request has been dealt with). Mandatory statutory provisions, in particular statutory retention periods, remain unaffected.
Online appointment booking
You can book appointments for introductory calls and coaching services on our website. For the booking we process the data you provide (name, email address, telephone number where applicable, and the chosen appointment and service). The processing takes place in order to take steps prior to entering into a contract or to perform the contract (Art. 6(1)(b) GDPR).
The booking data is stored on our own server and is not transmitted to external booking service providers. We send appointment confirmations and reminders by email to the address you provide. The data remains with us until the purpose for storage no longer applies; mandatory statutory provisions, in particular retention periods, remain unaffected.
Video conferencing (Google Meet)
For online coaching and online consultations we use the service Google Meet. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
When you take part in a video conference, Google processes personal data, in particular your IP address, device and browser information and audio and video data during the conversation. Participation is possible without a Google account; you receive the access link in advance by email. The conversations are not recorded.
The processing takes place in order to perform or initiate the coaching contract (Art. 6(1)(b) GDPR). Insofar as data is transferred to the USA, this is based on the adequacy decision for the EU-US Data Privacy Framework; Google LLC is certified under the framework. A data processing agreement under Art. 28 GDPR has been concluded with Google.
For more information see the Google privacy policy: policies.google.com/privacy.
Appointment synchronization with Google Calendar
To organize our appointments, we synchronize booked appointments with Google Calendar. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Only the name of the booked service and the date and time of the appointment are transferred. Your name, your email address and your telephone number are not transmitted to Google.
The processing takes place on the basis of our legitimate interest in reliable appointment organization free of double bookings (Art. 6(1)(f) GDPR). Further information on the handling of user data can be found in the Google privacy policy: policies.google.com/privacy.
Communication via WhatsApp Business
For communication with our clients and prospective clients we use, among other things, the service WhatsApp Business. The provider is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
Communication via WhatsApp only takes place if you contact us through this channel or expressly wish to use it. If you communicate with us via WhatsApp, your mobile number as well as the communication content and metadata (for example the time of the communication) are processed by WhatsApp; data may be transferred to Meta servers, including in the USA. The content of the communication is end-to-end encrypted. We point out that WhatsApp may gain access to the address book of the device used.
The processing takes place in order to perform the contract or to take steps prior to entering into a contract (Art. 6(1)(b) GDPR) and on the basis of our legitimate interest in fast and uncomplicated communication (Art. 6(1)(f) GDPR). Insofar as data is transferred to the USA, this is based on the adequacy decision for the EU-US Data Privacy Framework; Meta Platforms, Inc. is certified under the framework.
The use of WhatsApp is voluntary. On request we will of course communicate exclusively by email or telephone. We only exchange sensitive health data via WhatsApp insofar as you choose this channel yourself. For more information see the WhatsApp privacy policy: whatsapp.com/legal/privacy-policy-eea.
Content and data from the coaching
In the course of the coaching I process data that you provide to me so that we can work together. In addition to contact data, this may include information about your physical condition in particular (for example body measurements, weight, flexibility and strength values, earlier injuries or complaints) as well as training and progress data. The legal basis for contact, training and progress data is Art. 6(1)(b) GDPR (performance of the contract). Insofar as this is health data within the meaning of Art. 9 GDPR, I process it exclusively on the basis of your express consent under Art. 9(2)(a) GDPR. I obtain this consent separately before such data is first collected, as a rule at the beginning of the first session. Providing it is voluntary; without it, however, I cannot safely adapt the training to your condition. Consent can be withdrawn at any time with effect for the future. I do not collect any health data through the website itself.
I undertake to maintain confidentiality about everything discussed in the course of our work together. Sessions are not recorded unless this has been expressly and separately agreed with you. I treat my own notes and measurement records as confidential; they are not passed on to third parties and are deleted after the end of our work together and once statutory retention periods have expired.
Contract and invoice data
To handle and invoice booked services, I process contract data (name, address, booked service, period) and billing data. The processing takes place in order to perform the contract (Art. 6(1)(b) GDPR) and to comply with legal obligations (Art. 6(1)(c) GDPR), in particular retention obligations under tax and commercial law. Invoice data is retained in accordance with the statutory periods (as a rule eight or ten years) and then deleted.
Source: e-recht24.de