Privacy Policy
Last updated: 11 September 2026
1. Controller
The controller for the processing of personal data on this website is:
Atma Nada Yoga
Florencia Di Buduo & Hernán Sendra GbR
Schwetzinger Str. 3
69181 Leimen
Germany
Phone: +49 176 7218 1184
Email: info@atmanadayoga.com
We have not appointed a data protection officer. The conditions of Art. 37(1) GDPR and § 38(1) of the German Federal Data Protection Act (BDSG) are not met: fewer than 20 people in our business are permanently engaged in the automated processing of personal data, the processing of special categories of data is not our core activity, and no data protection impact assessment under Art. 35 GDPR is required. For any data protection question, please use the contact details above.
2. Definitions and principles
Personal data means any information relating to an identified or identifiable natural person. We process personal data only to the extent necessary to provide a functioning website and our services, or where you have given your consent.
This policy is in three parts: processing when you visit the website (section 3), when you contact us (section 4), and in the member area (sections 5 to 8). Sections 9 to 15 apply to all processing alike.
3. Visiting our website
3.1 Hosting and server log files
Our website is hosted by:
Hostinger International Ltd.
Jonavos g. 60C
44192 Kaunas
Lithuania
Hostinger processes personal data exclusively on our behalf as a processor, on the basis of a data processing agreement under Art. 28 GDPR (Data Processing Addendum, part of its terms of service): https://www.hostinger.com/legal/dpa
Each time a page is requested, the server automatically records the following in log files:
- IP address of the requesting device
- date and time of access
- name and URL of the file requested
- volume of data transferred and a message on whether the request succeeded
- the page visited previously (referrer), where transmitted
- browser and operating system used
Purpose: providing the website, ensuring system security and stability, and investigating misuse and technical faults.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and uninterrupted operation of the website.
Storage period: 7 days. After that our hosting provider deletes the log files automatically.
3.2 Encrypted transmission
This website uses TLS encryption throughout. You can recognise this by the padlock symbol and the https:// prefix in your browser’s address bar. The data you transmit to us therefore cannot be read by third parties.
3.3 Cookies and similar technologies
We use cookies and equivalent techniques (your browser’s local storage). The storage of information on your device, and access to it, is governed by § 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG):
- Strictly necessary storage takes place without your consent (§ 25(2) no. 2 TDDDG). This covers the record of your own cookie decision, the language you selected, your session in the member area, and restoring the last tab you had open within a page.
- All other access takes place only with your consent (§ 25(1) TDDDG). The subsequent processing of whatever is read rests on Art. 6(1)(a) GDPR.
To manage your consent we use the consent management tool Complianz. It is installed on our own server and transmits no data to the vendor. Complianz stores your decision for 365 days in cookies whose names begin with cmplz_.
You may withdraw or change your consent at any time with effect for the future, without giving reasons and without detriment, using the “Cookie settings” link in the footer of every page. A complete list of every cookie used, with its purpose and storage period, is in our Cookie Policy. In the event of contradiction or doubt, this Privacy Policy prevails.
3.4 Protection against spam and automated access (Cloudflare Turnstile)
On the sign-up, log-in and password reset pages, and in the contact form, we use Cloudflare Turnstile to distinguish automated requests (bots, bulk registrations, spam) from genuine human ones.
Provider: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, and Cloudflare Germany GmbH, Rosental 7, 80331 Munich, Germany.
When the check loads, the following is transmitted to Cloudflare: IP address, information about your browser and operating system, the time of access, and technical signals about how the device behaves in the browser. According to the provider, Turnstile performs no evaluation for advertising purposes and no cross-site recognition of users.
Purpose: defending our log-in and form functions against abusive automated access.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in protecting the website and our members’ data against automated attack. Without this protection, log-in forms would be left undefended against the automated trying of credentials.
Third-country transfer: Cloudflare, Inc. is established in the USA. The transfer takes place on the basis of the European Commission’s adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework, to which Cloudflare, Inc. is certified, supplemented by standard contractual clauses under Art. 46(2)(c) GDPR.
Further information: https://www.cloudflare.com/privacypolicy/
3.5 Fonts
Every font used on this website is stored locally on our own server and loaded from there. No connection to Google’s servers, or any other provider’s, takes place.
3.6 Links to external platforms
Our website contains links to our profiles on, or to the services of, the following providers:
- Google Maps
These are links only, not embedded content. Visiting our website therefore transmits no data to these providers and sets none of their cookies. Only when you click such a link does your browser establish a connection to the provider concerned; from that moment the provider, not we, is the controller for the processing. Please consult their own privacy information.
4. Contacting us
4.1 Contact form
Through our contact form we collect: name, email address, subject and your message. Before sending, the request is checked by Cloudflare Turnstile (see 3.4).
Your enquiry is not stored in this website’s database. It is forwarded solely as an email to the studio’s mailbox and handled there. It is sent via Hostinger’s mail server (see 3.1).
Purpose: handling your enquiry and any follow-up about it.
Legal basis: Art. 6(1)(b) GDPR where your enquiry is directed at concluding or performing a contract; otherwise Art. 6(1)(f) GDPR (legitimate interest in answering enquiries).
Storage period: we delete your enquiry once it has been finally dealt with and no statutory retention obligation applies, and in any event after six months.
Where your enquiry turns into a business matter — a booking, a complaint, or an agreement about prices — it counts as business correspondence and is kept for six years under § 147 (1) nos. 2 and 3 and 147 (3) of the German Fiscal Code (AO), after which it is deleted. During that time processing is restricted to meeting the retention obligation.
This is a different category from the invoicing and accounting records in section 6, which carry longer periods: a business letter is neither an accounting voucher nor a book.
4.2 Email, telephone and WhatsApp
If you contact us by email, by telephone or via WhatsApp, we process the data transmitted (depending on the route: name, telephone number, email address, content of the message) in order to deal with your request. Legal basis and storage period correspond to 4.1.
Where you contact us via WhatsApp, WhatsApp Ireland Limited, Merrion Road, Dublin 4, Ireland additionally processes traffic and usage data as its own controller under its own terms. We have no influence over this. If you wish to avoid it, please use email or the telephone.
5. Member account
5.1 Registration and email confirmation
An account is required to use the member area. On registration we collect: first name, last name, email address and a password of your choosing. The password is stored only as a cryptographic hash; it is not readable by us. Your username is generated automatically.
After registration we send an email containing a confirmation link. The account cannot be used until it is confirmed. This is how we establish that the address given really is yours.
Purpose: setting up and administering your member account, establishing ownership of the email address, access to registration and your attendance overview.
Legal basis: Art. 6(1)(b) GDPR (performance of the contract for use of the member area).
5.2 Personal information in the member form
The member area holds a form, “My details”, in four sections. The table below names every field, whether an entry is required, and the legal basis for each.
Section 1 — Personal information
| Information | Required | Purpose and legal basis |
|---|---|---|
| First name(s), last name(s) | yes | Attributing registrations, attendance and invoices. Art. 6(1)(b) GDPR |
| Date of birth | yes | Unambiguous identification where names coincide; checking participation requirements. Art. 6(1)(b) GDPR |
| Country of birth | no | Voluntary. Art. 6(1)(a) GDPR |
| Address, postcode, city, country | yes | Invoicing under § 14 of the German VAT Act. Art. 6(1)(b) and (c) GDPR |
| Telephone | yes | Reaching you if a class is cancelled or moved. Art. 6(1)(b) GDPR |
| Yoga experience | no | Adapting the class. Art. 6(1)(a) GDPR |
| Languages | no | Teaching in a language you understand. Art. 6(1)(a) GDPR |
Section 2 — Health information
This information is health data and therefore a special category of personal data within the meaning of Art. 9(1) GDPR. It is entirely voluntary. If you do not provide it you may still attend classes; however, the teacher cannot adapt the class to health limitations they know nothing about.
| Information | Required | Purpose and legal basis |
|---|---|---|
| Indication of an illness, injury or condition, and the explanation of it | no | Adapting the exercises, avoiding harm to health. Art. 9(2)(a) GDPR (explicit consent) together with Art. 6(1)(a) GDPR and § 22(1) no. 1(a) BDSG |
| Indication of regular medication, and the explanation of it | no | As above |
| Confirmation of your own fitness to participate | yes | A contractual declaration about your own responsibility. The declaration itself is not health data. Art. 6(1)(b) GDPR |
By entering and saving a health entry you give us your explicit consent under Art. 9(2)(a) GDPR to process that entry for the purposes named. You may withdraw this consent at any time by clearing the field in the member area or by writing to us; processing carried out before the withdrawal remains lawful. On retention after the end of your membership, see section 7.
We apply specific safeguards to this data: it is accessible only to the teacher taking the class and to the studio management, it is never carried in the body of a notification (see 5.5), and every access to archived entries is logged (see 7.3).
Section 3 — Consents
Every entry in this section is voluntary. Refusing or withdrawing a consent has no effect on your membership, on your registration for classes, or on your use of the member area.
| Information | Required | Purpose and legal basis |
|---|---|---|
| Being included in the studio’s contact address book (Microsoft Outlook) | no | Being reachable by email and telephone. Without this consent your details are not transmitted to Microsoft at all (see 8.1). Art. 6(1)(a) GDPR |
| Recording of online classes (Microsoft Teams / OneDrive) | no | Documenting a class and making it available afterwards. Taking part in an online class does not require this consent (see 8.3). Art. 6(1)(a) GDPR |
| Taking part in WhatsApp groups | no | Organisation and short-notice arrangements within the group. In a group, your name, profile picture and telephone number are visible to the other members. Your number is also stored in the address book of the studio’s phone, and WhatsApp matches that address book against Meta’s servers (see 8.2). Art. 6(1)(a) GDPR |
| WhatsApp number | no | Only where consent to the WhatsApp group has been given. Art. 6(1)(a) GDPR |
| Newsletter by email | no | Sending information about what we offer. Art. 6(1)(a) GDPR together with § 7(2) no. 2 of the German Unfair Competition Act (UWG) |
| Photographs and video | no | See section 10. Art. 6(1)(a) GDPR |
Section 4 — Personal responsibility
| Information | Required | Purpose and legal basis |
|---|---|---|
| Confirmation of the rules of conduct in class | yes | A contractual declaration. Art. 6(1)(b) GDPR |
5.3 Archive of changes
Every saved version of your entries is archived — together with the time and with the wording the form had at that time. This is necessary because a declaration only proves something if it is also established what was put to you when you made it; a question reworded later would otherwise retrospectively change an earlier answer.
Purpose: evidence of the declarations and consents given (Art. 7(1) GDPR: we must be able to demonstrate that consent was given), and defence against possible legal claims.
Legal basis: Art. 6(1)(c) and (f) GDPR; for health-related content additionally Art. 9(2)(f) GDPR.
Storage period: see section 7.
5.4 Obligation to review your information
Before you can use the member area for the first time, and periodically thereafter, we ask you to confirm or update your information. While that is outstanding the member area is not shown; the public pages of this website — timetable, activities, events — remain fully accessible.
Pursuant to Art. 13(2)(e) GDPR we inform you: the entries marked as required are necessary for the performance of the membership relationship. Without them we cannot provide the member area. The voluntary entries named in sections 2 and 3 are expressly not covered by this: they may be left blank without limiting your access.
5.5 Notifications to the studio
When you create an account, change your information, register for a class or cancel a registration, the studio’s mailbox receives a notification.
That notification names only which fields changed, never their contents. This is a deliberate limitation: an email mailbox is the one place our deletion periods cannot reach, and health information must not end up there.
Legal basis: Art. 6(1)(b) and (f) GDPR.
6. Class registration, attendance and payments
To perform your membership we process:
| Data | Purpose | Legal basis |
|---|---|---|
| Registrations for activities and events, registration status | Allocating places, planning capacity | Art. 6(1)(b) GDPR |
| Attendance per class | Billing, evidence of the service provided | Art. 6(1)(b) GDPR |
| Payments (amount, date, payment method, outstanding balance) | Billing, bookkeeping | Art. 6(1)(b) and (c) GDPR |
| Invoices, with the name and address as at the time of issue | Meeting invoicing and retention obligations | Art. 6(1)(c) GDPR together with § 14 UStG and § 147 of the German Fiscal Code (AO) |
Name and address are carried into the invoice as a copy. That copy survives even if your account is later deleted: an invoice whose recipient is removed after the fact no longer meets the statutory requirements.
Retention periods:
- Invoices and other accounting vouchers: 8 years (§ 147(3) sentence 1 AO and § 14b(1) UStG, each as in force since 1 January 2025).
- Books, records and annual accounts: 10 years (§ 147(1) no. 1 and 147(3) sentence 1 AO).
The period begins at the end of the calendar year in which the last entry was made or the invoice was issued. In practice we keep the whole set of accounting records for a uniform ten years, because invoices and books are not kept separately here and splitting them into eight- and ten-year sets would take more processing than it saved. During that time, processing of this data is restricted to meeting the retention obligation (Art. 18(1)(b) and 18(2) GDPR).
7. Deleting your account, and retention of health information
7.1 What is deleted
You can delete your account yourself at any time. Deleting it removes your user account, your credentials and all the information listed in section 5.2 insofar as it is stored in your profile. Your information thereby no longer exists in any view of this website — member area, teacher view, exports.
If no payment or invoice data and no archived declarations exist for you, everything is deleted with no exception.
7.2 What is retained, and why
Two groups of data are not deleted but restricted in processing (blocked):
Invoice and payment data — for the statutory periods stated in section 6. Legal basis: Art. 17(3)(b) GDPR.
Health information, consents, and the name and date of birth needed to attribute them — for 30 years. Under § 199(2) of the German Civil Code (BGB), a claim for damages for injury to life, body, health or freedom can be brought up to 30 years after the harmful event. If we had to defend against such a claim, your own declaration at the time about your state of health and your fitness to participate would be the decisive evidence. Art. 17(3)(e) GDPR expressly exempts processing necessary for the defence of legal claims from the duty to erase; for health data, Art. 9(2)(f) GDPR supplies the permission this requires.
The period runs from your last attended class — the last moment at which such an event could have occurred at all. After it expires the data is deleted automatically and permanently.
7.3 What “blocked” means in practice
During that time:
- The data is used for no purpose other than defending against legal claims.
- It is not visible to teachers or staff in normal operation and appears in no list, no export and no report.
- There is exactly one route of access, open only to the studio management. Every access is logged — with the time, the person accessing, and the name searched for, including where the search found nothing. That log cannot be altered or deleted.
- You retain your right of access under Art. 15 GDPR for this data too.
Before you confirm deletion, this is shown to you again separately. That notice is itself archived in the version you saw.
8. The studio’s address book
8.1 Synchronisation with Microsoft Outlook
We keep the studio’s address book in Microsoft Outlook, so that members are reachable on the device from which we run the WhatsApp groups.
This happens only with your consent. Without the “being included in the studio’s contact address book” consent, nothing about you is transmitted to Microsoft at all; if you withdraw it later, the contact already created is deleted, not merely left un-updated. Your member account, your registrations and the whole member area go on working regardless.
With your consent we transfer, from your profile:
- first and last name
- email address
- telephone number only where you have consented to taking part in WhatsApp groups and have given a number
If you withdraw that consent, the number is deleted from the existing contact, not merely left un-updated. If you delete your account, the contact is deleted in Outlook.
The transfer takes place server-to-server only, through the Microsoft Graph interface. No script is loaded in your browser and no cookie is set.
Recipient: Microsoft, through a personal Microsoft account (Outlook.com). Microsoft acts not as our processor but as its own controller, on the basis of the Microsoft Services Agreement and the Microsoft Privacy Statement. That means Microsoft decides for itself what further purposes it processes the data in its services for — running and improving them, and security, among others — and we cannot limit that by contract. There is no processing agreement under Art. 28 GDPR for this account.
We say so explicitly because you need to know it before you give the consent. If you would rather not, do not give it: your account and your registrations go on working exactly as before, and we write to you at your account email address.
Further information: https://privacy.microsoft.com/en-gb/privacystatement
Legal basis: Art. 6(1)(b) GDPR for name and email address (performance of the membership relationship); Art. 6(1)(a) GDPR for the telephone number.
Third-country transfer: Microsoft also processes data outside the EU. The basis is the European Commission’s adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework, to which Microsoft Corporation is certified, supplemented by standard contractual clauses under Art. 46(2)(c) GDPR.
8.2 From the address book to WhatsApp
The address book in section 8.1 lives on the phone from which we run the WhatsApp groups. WhatsApp reads that phone’s address book and matches the numbers in it against Meta’s servers. This happens whether or not you are ever added to a group: once your number is in the address book, Meta receives it.
Recipient: WhatsApp Ireland Limited, Merrion Road, Dublin 4, Ireland, as its own controller and under its own terms. We have no influence over this.
Legal basis: Art. 6(1)(a) GDPR — your consent to take part in WhatsApp groups. Without that consent your number never reaches the address book in the first place, and WhatsApp does not receive it from us.
Withdrawal: you may withdraw the consent at any time, and your number is then removed from the contact and so from the address book. What Meta has already received we cannot retrieve — only WhatsApp’s own terms govern that, and you would need to approach them directly.
If you would like to attend classes without Meta receiving your number, simply do not give this consent. You can still reach us by email and telephone, and we can still reach you.
8.3 Online classes (Microsoft Teams) and recordings (OneDrive)
Online classes and meetings run through Microsoft Teams; the associated file storage is Microsoft OneDrive.
The legal basis for delivering an online class you want to attend is Art. 6(1)(b) GDPR: you booked the class, and Teams is the means by which we provide it. We need no consent for that and we ask for none — a consent without which you would not receive the service you booked would not be freely given (Art. 7(4) GDPR).
The legal basis for a recording is different: Art. 6(1)(a) GDPR, your separate consent. You can take part in an online class without giving it; in that case we do not record you, or the recording is not used. Withdrawal takes effect for the future.
Recordings may contain your image and voice. We keep them only as long as the purpose they were made for requires.
9. Recipients and internal tools
Beyond the entities named in sections 3 to 8, we disclose personal data only as set out below or where we are legally obliged to.
| Recipient | Role | Receives | Third country |
|---|---|---|---|
| Hostinger International Ltd., Kaunas, Lithuania | Processor (hosting, email delivery) | Server log files, all data stored on the website, outgoing email | no (EU) |
| Cloudflare, Inc., San Francisco, USA | Own controller / processor for bot protection | IP address, device and browser signals on the pages named in 3.4 | yes — EU-US DPF, SCCs |
| Microsoft (personal Microsoft account) | Its own controller, not our processor | Name, email, telephone number where applicable — only with consent | yes — EU-US DPF |
| WhatsApp Ireland Limited, Dublin, Ireland | Own controller | Your number from our phone’s address book, and name and profile picture within a group — only with consent | yes — per the provider’s terms |
| Tax adviser and, where applicable, tax authorities | Legal obligation / processing agreement | Invoice and payment data | no |
For internal administration we additionally use two Microsoft services: Microsoft Teams for online classes and meetings, and Microsoft OneDrive, the file storage in which Teams keeps its content. The personal data processed there is customer master data, payment information and photographs. Google Drive and Google Meet are no longer used.
Legal basis: Art. 6(1)(b) GDPR, and for photographs and recordings Art. 6(1)(a) GDPR. These services also run on the same personal Microsoft account, so here too Microsoft is its own controller and not our processor, and there is no agreement under Art. 28 GDPR. For the transfer to the USA, the European Commission’s adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework applies, to which Microsoft Corporation is certified.
Health information is not stored in these services. It remains solely in this website’s database and is subject to the limitations described in 5.2 and 7.3. This also applies to information that reaches us another way: if we receive a health-related message by email or chat, it is not moved into a cloud folder.
10. Photographs and video
Photographs and video are taken during our activities and used for documentation and publicity — on this website, on social media and in informational material.
The legal basis is your consent under Art. 6(1)(a) GDPR. That consent is voluntary and can be withdrawn at any time with effect for the future, by email to the address in section 1 or by unticking the box in the member form. After a withdrawal we make no further use of the images concerned and remove them from our own publications so far as we are able.
Anyone who does not wish to be recorded will not be deliberately photographed or filmed. If someone appears in a recording unintentionally, it will not be used, or their face will be obscured.
We point out expressly: on publication to social media (Instagram, Facebook), the image is transmitted to the provider concerned and processed by it under its own terms, including outside the EU. We have no influence over further distribution by third parties.
11. Storage periods at a glance
| Data | Storage period |
|---|---|
| Server log files | 7 days |
| Cookie consent | 365 days, withdrawable at any time |
| Contact form and other enquiries | Until dealt with, and at the latest 6 months; as business correspondence, 6 years (§ 147 AO) |
| Member account and profile information | Until you delete the account, or the membership ends |
| Registrations and attendance | Until the account is deleted, where no payment data exists |
| Invoices and accounting vouchers | 8 years (§ 147(3) AO, § 14b UStG) |
| Books and annual accounts | 10 years (§ 147(1) no. 1 AO) |
| Health information and consents after account deletion | 30 years from the last attended class (§ 199(2) BGB), with processing restricted |
| Log of accesses to blocked records | Indefinite — it has to outlive the records it documents, and contains no health data itself |
12. Your rights
You have the following rights against us:
- Access to the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data, or completion of incomplete data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR), unless one of the grounds in Art. 17(3) GDPR applies — on the two cases where that is so here, see section 7
- Restriction of processing (Art. 18 GDPR)
- Data portability in a structured, commonly used, machine-readable format (Art. 20 GDPR)
- Withdrawal of a consent at any time with effect for the future (Art. 7(3) GDPR). Withdrawal is as easy as giving consent: untick the box in the member form, or send us an email. The lawfulness of processing carried out before the withdrawal is unaffected.
- Complaint to a data protection supervisory authority (Art. 77 GDPR)
To exercise these rights, use the contact details in section 1. We respond within one month.
Right to object under Art. 21 GDPR
Where we process your data on the basis of a legitimate interest under Art. 6(1)(f) GDPR, you have the right to object to that processing at any time on grounds relating to your particular situation. We will then stop processing the data unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
An objection in writing to the email address in section 1 is sufficient; giving reasons helps us weigh the matter but is not a condition of its effectiveness.
Competent supervisory authority
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit
Baden-Württemberg
Lautenschlagerstraße 20
70173 Stuttgart, Germany
Phone: +49 711 615541-0
Email: poststelle@lfdi.bwl.de
https://www.baden-wuerttemberg.datenschutz.de
Independently of this, you may also contact the supervisory authority where you live or work.
13. No automated decision-making
No automated individual decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. We do not evaluate you automatically, build no usage profiles, and use no advertising or analytics technologies.
14. Changes to this Privacy Policy
We update this policy when the processing it describes changes. The version published here at any given time governs; the date at the top states which version that is. Where a change affects a consent, we ask for it again and do not rely on the earlier one.
15. Language versions
This Privacy Policy is available in German, Spanish and English. Only the German version is legally binding.