Information on the processing of personal data in accordance with Art. 13 GDPR for customers of NHS Personal Training GmbH

NHS Personal Training GmbH attaches great importance to the protection of your personal data. In the following, we would like to give you an overview of the processing of your personal data by NHS Personal Training GmbH and the rights to which you are entitled under the data protection regulations.

 

1. Person responsible for data processing

NHS Personal Training GmbH
AG Charlottenburg (HRB 260252)
Vert. D. of the managing director Mr.
Alexander Brikman
Lilienthalallee 5-7, 80807 Munich
Phone: 0176-81253942
E-mail: info@newhealthsociety.com

 

2. Purposes of data processing

Your personal data will be processed for the following purposes:

  • Contract management and processing of your membership:
    Collection and management of your data for the conclusion and execution of the membership contract (e.g. name, address, contact details, bank details).
  • Scheduling and coordination:
    Management of training plans, arrangement and organization of your personal training appointments.
  • Communication:
    Use of your contact details to inform you of important information (e.g. contract changes, appointment cancellations).
  • Updating training and nutrition plans:
    Creation and adaptation of individual training and nutrition plans during the contract period.
  • Billing and payment processing:
    Carrying out the SEPA direct debit for the monthly membership fees and, if necessary, dunning in the event of payment arrears.
  • Advertising purposes after consent:
    Use of your photos and videos on our social media channels or to promote events, provided you have expressly consented to this.
  • Compliance with legal obligations:
    Fulfillment of retention periods and statutory documentation obligations (e.g. under tax or commercial law).
  • Enforcement of our legitimate interests:
    Pursuing legitimate interests, e.g. receivables management in the event of payment defaults or ensuring proper operation (e.g. compliance with house rules).

 

3. Legal bases of the processing

We process your personal data for the following purposes and on the following legal bases:

 

Purpose of processing Legal basis
Processing of membership and contract management Art. 6 para. 1 lit. b) GDPR (fulfillment of a contract)
SEPA direct debit and billing of contributions Art. 6 para. 1 lit. b) GDPR (contract fulfillment)
Communication with you (e.g., making appointments) Art. 6 para. 1 lit. b) GDPR (contract fulfillment)
Updating training and nutrition plans Art. 6 para. 1 lit. b) GDPR (contract fulfillment)
Protection of legitimate interests, e.g., claims management Art. 6 para. 1 lit. f) GDPR (legitimate interest)
Fulfillment of legal retention requirements (e.g., tax law) Art. 6 para. 1 lit. c) GDPR (legal obligation)
Use of photos/videos for social media (after consent) Art. 6 para. 1 lit. a) GDPR (consent)

 

4. Recipients of your data

Your data will only be passed on if this is necessary for the fulfillment of the contract or for legal reasons.
Recipients may be:

  • Banking institutions for processing SEPA direct debits.
  • IT service provider for the operation of our software and communication systems.
  • Collection service provider in the event of payment defaults.
  • Tax consultants and authorities to fulfill legal obligations.

Your data will only be transferred to third parties for purposes other than those mentioned if you have expressly consented to this or if we are legally obliged to do so.

 

5. Data transfer to third countries

Your personal data will only be transferred to third countries outside the EU or the EEA if this is necessary to fulfill the contract or if you have expressly consented to this.

 

6. Storage duration of your data

Your personal data will only be stored for as long as is necessary for the fulfillment of contractual purposes or legal obligations. After termination of membership and expiry of the statutory retention periods (e.g. 10 years for tax documents), the data will be deleted.

 

7. Your rights as a data subject

You have the following rights under the GDPR:

  • Right to information (Art. 15 GDPR): You can request confirmation as to whether your personal data is being processed.
  • Right to rectification (Art. 16 GDPR): You have the right to rectification of incorrect or incomplete data.
  • Right to erasure (Art. 17 GDPR): Under certain conditions, you can request the erasure of your data.
  • Right to restriction of processing (Art. 18 GDPR): You can request the restriction of the processing of your data.
  • Right to data portability (Art. 20 GDPR): You have the right to receive the data you have provided to us in a structured, commonly used and machine-readable format.

 

8. Right to withdraw consent

If you have given us your consent to process your data (e.g. for the publication of images on social media), you can revoke this consent at any time with effect for the future.

 

9. Information on the right to object pursuant to Art. 21 GDPR

You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on Article 6(1)(e) GDPR (data processing in the public interest) and Article 6(1)(f) GDPR (data processing on the basis of a balancing of interests); this also applies to profiling based on this provision within the meaning of Article 4(4) GDPR.
If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defense of legal claims.
The objection can be made informally and should be addressed to the head office.

 

10. Right to lodge a complaint with the supervisory authority

Bavarian State Office for Data Protection Supervision
Promenade 18
91522 Ansbach
Germany
Phone: +49 (0) 981 180093-0
Fax: +49 (0) 981 180093-800
E-mail: poststelle@lda.bayern.de
Postal address:
P.O. Box 1349
91504 Ansbach
Germany

 

11. Provision of data and consequences of non-provision

The provision of certain data (e.g. name, address, bank details) is required for the conclusion and execution of the membership. Without this data, it is not possible to execute the contract.

 

12. Automated decision making / profiling

Automated decision-making or profiling within the meaning of Art. 22 GDPR does not take place.