Privacy Policy

Last updated: 11 September 2026

1. Controller

The controller for the processing of personal data on this website is:

Atma Nada Yoga
Florencia Di Buduo & Hernán Sendra GbR
Schwetzinger Str. 3
69181 Leimen
Germany
Phone: +49 176 7218 1184
Email: info@atmanadayoga.com

We have not appointed a data protection officer. The conditions of Art. 37(1) GDPR and § 38(1) of the German Federal Data Protection Act (BDSG) are not met: fewer than 20 people in our business are permanently engaged in the automated processing of personal data, the processing of special categories of data is not our core activity, and no data protection impact assessment under Art. 35 GDPR is required. For any data protection question, please use the contact details above.

2. Definitions and principles

Personal data means any information relating to an identified or identifiable natural person. We process personal data only to the extent necessary to provide a functioning website and our services, or where you have given your consent.

This policy is in three parts: processing when you visit the website (section 3), when you contact us (section 4), and in the member area (sections 5 to 8). Sections 9 to 15 apply to all processing alike.

3. Visiting our website

3.1 Hosting and server log files

Our website is hosted by:

Hostinger International Ltd.
Jonavos g. 60C
44192 Kaunas
Lithuania

Hostinger processes personal data exclusively on our behalf as a processor, on the basis of a data processing agreement under Art. 28 GDPR (Data Processing Addendum, part of its terms of service): https://www.hostinger.com/legal/dpa

Each time a page is requested, the server automatically records the following in log files:

  • IP address of the requesting device
  • date and time of access
  • name and URL of the file requested
  • volume of data transferred and a message on whether the request succeeded
  • the page visited previously (referrer), where transmitted
  • browser and operating system used

Purpose: providing the website, ensuring system security and stability, and investigating misuse and technical faults.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and uninterrupted operation of the website.

Storage period: 7 days. After that our hosting provider deletes the log files automatically.

3.2 Encrypted transmission

This website uses TLS encryption throughout. You can recognise this by the padlock symbol and the https:// prefix in your browser’s address bar. The data you transmit to us therefore cannot be read by third parties.

3.3 Cookies and similar technologies

We use cookies and equivalent techniques (your browser’s local storage). The storage of information on your device, and access to it, is governed by § 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG):

  • Strictly necessary storage takes place without your consent (§ 25(2) no. 2 TDDDG). This covers the record of your own cookie decision, the language you selected, your session in the member area, and restoring the last tab you had open within a page.
  • All other access takes place only with your consent (§ 25(1) TDDDG). The subsequent processing of whatever is read rests on Art. 6(1)(a) GDPR.

To manage your consent we use the consent management tool Complianz. It is installed on our own server and transmits no data to the vendor. Complianz stores your decision for 365 days in cookies whose names begin with cmplz_.

You may withdraw or change your consent at any time with effect for the future, without giving reasons and without detriment, using the “Cookie settings” link in the footer of every page. A complete list of every cookie used, with its purpose and storage period, is in our Cookie Policy. In the event of contradiction or doubt, this Privacy Policy prevails.

3.4 Protection against spam and automated access (Cloudflare Turnstile)

On the sign-up, log-in and password reset pages, and in the contact form, we use Cloudflare Turnstile to distinguish automated requests (bots, bulk registrations, spam) from genuine human ones.

Provider: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, and Cloudflare Germany GmbH, Rosental 7, 80331 Munich, Germany.

When the check loads, the following is transmitted to Cloudflare: IP address, information about your browser and operating system, the time of access, and technical signals about how the device behaves in the browser. According to the provider, Turnstile performs no evaluation for advertising purposes and no cross-site recognition of users.

Purpose: defending our log-in and form functions against abusive automated access.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in protecting the website and our members’ data against automated attack. Without this protection, log-in forms would be left undefended against the automated trying of credentials.

Third-country transfer: Cloudflare, Inc. is established in the USA. The transfer takes place on the basis of the European Commission’s adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework, to which Cloudflare, Inc. is certified, supplemented by standard contractual clauses under Art. 46(2)(c) GDPR.

Further information: https://www.cloudflare.com/privacypolicy/

3.5 Fonts

Every font used on this website is stored locally on our own server and loaded from there. No connection to Google’s servers, or any other provider’s, takes place.

3.6 Links to external platforms

Our website contains links to our profiles on, or to the services of, the following providers:

  • Instagram
  • Facebook
  • WhatsApp
  • Google Maps

These are links only, not embedded content. Visiting our website therefore transmits no data to these providers and sets none of their cookies. Only when you click such a link does your browser establish a connection to the provider concerned; from that moment the provider, not we, is the controller for the processing. Please consult their own privacy information.

4. Contacting us

4.1 Contact form

Through our contact form we collect: name, email address, subject and your message. Before sending, the request is checked by Cloudflare Turnstile (see 3.4).

Your enquiry is not stored in this website’s database. It is forwarded solely as an email to the studio’s mailbox and handled there. It is sent via Hostinger’s mail server (see 3.1).

Purpose: handling your enquiry and any follow-up about it.

Legal basis: Art. 6(1)(b) GDPR where your enquiry is directed at concluding or performing a contract; otherwise Art. 6(1)(f) GDPR (legitimate interest in answering enquiries).

Storage period: we delete your enquiry once it has been finally dealt with and no statutory retention obligation applies, and in any event after six months.

Where your enquiry turns into a business matter — a booking, a complaint, or an agreement about prices — it counts as business correspondence and is kept for six years under § 147 (1) nos. 2 and 3 and 147 (3) of the German Fiscal Code (AO), after which it is deleted. During that time processing is restricted to meeting the retention obligation.

This is a different category from the invoicing and accounting records in section 6, which carry longer periods: a business letter is neither an accounting voucher nor a book.

4.2 Email, telephone and WhatsApp

If you contact us by email, by telephone or via WhatsApp, we process the data transmitted (depending on the route: name, telephone number, email address, content of the message) in order to deal with your request. Legal basis and storage period correspond to 4.1.

Where you contact us via WhatsApp, WhatsApp Ireland Limited, Merrion Road, Dublin 4, Ireland additionally processes traffic and usage data as its own controller under its own terms. We have no influence over this. If you wish to avoid it, please use email or the telephone.

5. Member account

5.1 Registration and email confirmation

An account is required to use the member area. On registration we collect: first name, last name, email address and a password of your choosing. The password is stored only as a cryptographic hash; it is not readable by us. Your username is generated automatically.

After registration we send an email containing a confirmation link. The account cannot be used until it is confirmed. This is how we establish that the address given really is yours.

Purpose: setting up and administering your member account, establishing ownership of the email address, access to registration and your attendance overview.

Legal basis: Art. 6(1)(b) GDPR (performance of the contract for use of the member area).

5.2 Personal information in the member form

The member area holds a form, “My details”, in four sections. The table below names every field, whether an entry is required, and the legal basis for each.

Section 1 — Personal information

InformationRequiredPurpose and legal basis
First name(s), last name(s)yesAttributing registrations, attendance and invoices. Art. 6(1)(b) GDPR
Date of birthyesUnambiguous identification where names coincide; checking participation requirements. Art. 6(1)(b) GDPR
Country of birthnoVoluntary. Art. 6(1)(a) GDPR
Address, postcode, city, countryyesInvoicing under § 14 of the German VAT Act. Art. 6(1)(b) and (c) GDPR
TelephoneyesReaching you if a class is cancelled or moved. Art. 6(1)(b) GDPR
Yoga experiencenoAdapting the class. Art. 6(1)(a) GDPR
LanguagesnoTeaching in a language you understand. Art. 6(1)(a) GDPR

Section 2 — Health information

This information is health data and therefore a special category of personal data within the meaning of Art. 9(1) GDPR. It is entirely voluntary. If you do not provide it you may still attend classes; however, the teacher cannot adapt the class to health limitations they know nothing about.

InformationRequiredPurpose and legal basis
Indication of an illness, injury or condition, and the explanation of itnoAdapting the exercises, avoiding harm to health. Art. 9(2)(a) GDPR (explicit consent) together with Art. 6(1)(a) GDPR and § 22(1) no. 1(a) BDSG
Indication of regular medication, and the explanation of itnoAs above
Confirmation of your own fitness to participateyesA contractual declaration about your own responsibility. The declaration itself is not health data. Art. 6(1)(b) GDPR

By entering and saving a health entry you give us your explicit consent under Art. 9(2)(a) GDPR to process that entry for the purposes named. You may withdraw this consent at any time by clearing the field in the member area or by writing to us; processing carried out before the withdrawal remains lawful. On retention after the end of your membership, see section 7.

We apply specific safeguards to this data: it is accessible only to the teacher taking the class and to the studio management, it is never carried in the body of a notification (see 5.5), and every access to archived entries is logged (see 7.3).

Section 3 — Consents

Every entry in this section is voluntary. Refusing or withdrawing a consent has no effect on your membership, on your registration for classes, or on your use of the member area.

InformationRequiredPurpose and legal basis
Being included in the studio’s contact address book (Microsoft Outlook)noBeing reachable by email and telephone. Without this consent your details are not transmitted to Microsoft at all (see 8.1). Art. 6(1)(a) GDPR
Recording of online classes (Microsoft Teams / OneDrive)noDocumenting a class and making it available afterwards. Taking part in an online class does not require this consent (see 8.3). Art. 6(1)(a) GDPR
Taking part in WhatsApp groupsnoOrganisation and short-notice arrangements within the group. In a group, your name, profile picture and telephone number are visible to the other members. Your number is also stored in the address book of the studio’s phone, and WhatsApp matches that address book against Meta’s servers (see 8.2). Art. 6(1)(a) GDPR
WhatsApp numbernoOnly where consent to the WhatsApp group has been given. Art. 6(1)(a) GDPR
Newsletter by emailnoSending information about what we offer. Art. 6(1)(a) GDPR together with § 7(2) no. 2 of the German Unfair Competition Act (UWG)
Photographs and videonoSee section 10. Art. 6(1)(a) GDPR

Section 4 — Personal responsibility

InformationRequiredPurpose and legal basis
Confirmation of the rules of conduct in classyesA contractual declaration. Art. 6(1)(b) GDPR

5.3 Archive of changes

Every saved version of your entries is archived — together with the time and with the wording the form had at that time. This is necessary because a declaration only proves something if it is also established what was put to you when you made it; a question reworded later would otherwise retrospectively change an earlier answer.

Purpose: evidence of the declarations and consents given (Art. 7(1) GDPR: we must be able to demonstrate that consent was given), and defence against possible legal claims.

Legal basis: Art. 6(1)(c) and (f) GDPR; for health-related content additionally Art. 9(2)(f) GDPR.

Storage period: see section 7.

5.4 Obligation to review your information

Before you can use the member area for the first time, and periodically thereafter, we ask you to confirm or update your information. While that is outstanding the member area is not shown; the public pages of this website — timetable, activities, events — remain fully accessible.

Pursuant to Art. 13(2)(e) GDPR we inform you: the entries marked as required are necessary for the performance of the membership relationship. Without them we cannot provide the member area. The voluntary entries named in sections 2 and 3 are expressly not covered by this: they may be left blank without limiting your access.

5.5 Notifications to the studio

When you create an account, change your information, register for a class or cancel a registration, the studio’s mailbox receives a notification.

That notification names only which fields changed, never their contents. This is a deliberate limitation: an email mailbox is the one place our deletion periods cannot reach, and health information must not end up there.

Legal basis: Art. 6(1)(b) and (f) GDPR.

6. Class registration, attendance and payments

To perform your membership we process:

DataPurposeLegal basis
Registrations for activities and events, registration statusAllocating places, planning capacityArt. 6(1)(b) GDPR
Attendance per classBilling, evidence of the service providedArt. 6(1)(b) GDPR
Payments (amount, date, payment method, outstanding balance)Billing, bookkeepingArt. 6(1)(b) and (c) GDPR
Invoices, with the name and address as at the time of issueMeeting invoicing and retention obligationsArt. 6(1)(c) GDPR together with § 14 UStG and § 147 of the German Fiscal Code (AO)

Name and address are carried into the invoice as a copy. That copy survives even if your account is later deleted: an invoice whose recipient is removed after the fact no longer meets the statutory requirements.

Retention periods:

  • Invoices and other accounting vouchers: 8 years (§ 147(3) sentence 1 AO and § 14b(1) UStG, each as in force since 1 January 2025).
  • Books, records and annual accounts: 10 years (§ 147(1) no. 1 and 147(3) sentence 1 AO).

The period begins at the end of the calendar year in which the last entry was made or the invoice was issued. In practice we keep the whole set of accounting records for a uniform ten years, because invoices and books are not kept separately here and splitting them into eight- and ten-year sets would take more processing than it saved. During that time, processing of this data is restricted to meeting the retention obligation (Art. 18(1)(b) and 18(2) GDPR).

7. Deleting your account, and retention of health information

7.1 What is deleted

You can delete your account yourself at any time. Deleting it removes your user account, your credentials and all the information listed in section 5.2 insofar as it is stored in your profile. Your information thereby no longer exists in any view of this website — member area, teacher view, exports.

If no payment or invoice data and no archived declarations exist for you, everything is deleted with no exception.

7.2 What is retained, and why

Two groups of data are not deleted but restricted in processing (blocked):

Invoice and payment data — for the statutory periods stated in section 6. Legal basis: Art. 17(3)(b) GDPR.

Health information, consents, and the name and date of birth needed to attribute them — for 30 years. Under § 199(2) of the German Civil Code (BGB), a claim for damages for injury to life, body, health or freedom can be brought up to 30 years after the harmful event. If we had to defend against such a claim, your own declaration at the time about your state of health and your fitness to participate would be the decisive evidence. Art. 17(3)(e) GDPR expressly exempts processing necessary for the defence of legal claims from the duty to erase; for health data, Art. 9(2)(f) GDPR supplies the permission this requires.

The period runs from your last attended class — the last moment at which such an event could have occurred at all. After it expires the data is deleted automatically and permanently.

7.3 What “blocked” means in practice

During that time:

  • The data is used for no purpose other than defending against legal claims.
  • It is not visible to teachers or staff in normal operation and appears in no list, no export and no report.
  • There is exactly one route of access, open only to the studio management. Every access is logged — with the time, the person accessing, and the name searched for, including where the search found nothing. That log cannot be altered or deleted.
  • You retain your right of access under Art. 15 GDPR for this data too.

Before you confirm deletion, this is shown to you again separately. That notice is itself archived in the version you saw.

8. The studio’s address book

8.1 Synchronisation with Microsoft Outlook

We keep the studio’s address book in Microsoft Outlook, so that members are reachable on the device from which we run the WhatsApp groups.

This happens only with your consent. Without the “being included in the studio’s contact address book” consent, nothing about you is transmitted to Microsoft at all; if you withdraw it later, the contact already created is deleted, not merely left un-updated. Your member account, your registrations and the whole member area go on working regardless.

With your consent we transfer, from your profile:

  • first and last name
  • email address
  • telephone number only where you have consented to taking part in WhatsApp groups and have given a number

If you withdraw that consent, the number is deleted from the existing contact, not merely left un-updated. If you delete your account, the contact is deleted in Outlook.

The transfer takes place server-to-server only, through the Microsoft Graph interface. No script is loaded in your browser and no cookie is set.

Recipient: Microsoft, through a personal Microsoft account (Outlook.com). Microsoft acts not as our processor but as its own controller, on the basis of the Microsoft Services Agreement and the Microsoft Privacy Statement. That means Microsoft decides for itself what further purposes it processes the data in its services for — running and improving them, and security, among others — and we cannot limit that by contract. There is no processing agreement under Art. 28 GDPR for this account.

We say so explicitly because you need to know it before you give the consent. If you would rather not, do not give it: your account and your registrations go on working exactly as before, and we write to you at your account email address.

Further information: https://privacy.microsoft.com/en-gb/privacystatement

Legal basis: Art. 6(1)(b) GDPR for name and email address (performance of the membership relationship); Art. 6(1)(a) GDPR for the telephone number.

Third-country transfer: Microsoft also processes data outside the EU. The basis is the European Commission’s adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework, to which Microsoft Corporation is certified, supplemented by standard contractual clauses under Art. 46(2)(c) GDPR.

8.2 From the address book to WhatsApp

The address book in section 8.1 lives on the phone from which we run the WhatsApp groups. WhatsApp reads that phone’s address book and matches the numbers in it against Meta’s servers. This happens whether or not you are ever added to a group: once your number is in the address book, Meta receives it.

Recipient: WhatsApp Ireland Limited, Merrion Road, Dublin 4, Ireland, as its own controller and under its own terms. We have no influence over this.

Legal basis: Art. 6(1)(a) GDPR — your consent to take part in WhatsApp groups. Without that consent your number never reaches the address book in the first place, and WhatsApp does not receive it from us.

Withdrawal: you may withdraw the consent at any time, and your number is then removed from the contact and so from the address book. What Meta has already received we cannot retrieve — only WhatsApp’s own terms govern that, and you would need to approach them directly.

If you would like to attend classes without Meta receiving your number, simply do not give this consent. You can still reach us by email and telephone, and we can still reach you.

8.3 Online classes (Microsoft Teams) and recordings (OneDrive)

Online classes and meetings run through Microsoft Teams; the associated file storage is Microsoft OneDrive.

The legal basis for delivering an online class you want to attend is Art. 6(1)(b) GDPR: you booked the class, and Teams is the means by which we provide it. We need no consent for that and we ask for none — a consent without which you would not receive the service you booked would not be freely given (Art. 7(4) GDPR).

The legal basis for a recording is different: Art. 6(1)(a) GDPR, your separate consent. You can take part in an online class without giving it; in that case we do not record you, or the recording is not used. Withdrawal takes effect for the future.

Recordings may contain your image and voice. We keep them only as long as the purpose they were made for requires.

9. Recipients and internal tools

Beyond the entities named in sections 3 to 8, we disclose personal data only as set out below or where we are legally obliged to.

RecipientRoleReceivesThird country
Hostinger International Ltd., Kaunas, LithuaniaProcessor (hosting, email delivery)Server log files, all data stored on the website, outgoing emailno (EU)
Cloudflare, Inc., San Francisco, USAOwn controller / processor for bot protectionIP address, device and browser signals on the pages named in 3.4yes — EU-US DPF, SCCs
Microsoft (personal Microsoft account)Its own controller, not our processorName, email, telephone number where applicable — only with consentyes — EU-US DPF
WhatsApp Ireland Limited, Dublin, IrelandOwn controllerYour number from our phone’s address book, and name and profile picture within a group — only with consentyes — per the provider’s terms
Tax adviser and, where applicable, tax authoritiesLegal obligation / processing agreementInvoice and payment datano

For internal administration we additionally use two Microsoft services: Microsoft Teams for online classes and meetings, and Microsoft OneDrive, the file storage in which Teams keeps its content. The personal data processed there is customer master data, payment information and photographs. Google Drive and Google Meet are no longer used.

Legal basis: Art. 6(1)(b) GDPR, and for photographs and recordings Art. 6(1)(a) GDPR. These services also run on the same personal Microsoft account, so here too Microsoft is its own controller and not our processor, and there is no agreement under Art. 28 GDPR. For the transfer to the USA, the European Commission’s adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework applies, to which Microsoft Corporation is certified.

Health information is not stored in these services. It remains solely in this website’s database and is subject to the limitations described in 5.2 and 7.3. This also applies to information that reaches us another way: if we receive a health-related message by email or chat, it is not moved into a cloud folder.

10. Photographs and video

Photographs and video are taken during our activities and used for documentation and publicity — on this website, on social media and in informational material.

The legal basis is your consent under Art. 6(1)(a) GDPR. That consent is voluntary and can be withdrawn at any time with effect for the future, by email to the address in section 1 or by unticking the box in the member form. After a withdrawal we make no further use of the images concerned and remove them from our own publications so far as we are able.

Anyone who does not wish to be recorded will not be deliberately photographed or filmed. If someone appears in a recording unintentionally, it will not be used, or their face will be obscured.

We point out expressly: on publication to social media (Instagram, Facebook), the image is transmitted to the provider concerned and processed by it under its own terms, including outside the EU. We have no influence over further distribution by third parties.

11. Storage periods at a glance

DataStorage period
Server log files7 days
Cookie consent365 days, withdrawable at any time
Contact form and other enquiriesUntil dealt with, and at the latest 6 months; as business correspondence, 6 years (§ 147 AO)
Member account and profile informationUntil you delete the account, or the membership ends
Registrations and attendanceUntil the account is deleted, where no payment data exists
Invoices and accounting vouchers8 years (§ 147(3) AO, § 14b UStG)
Books and annual accounts10 years (§ 147(1) no. 1 AO)
Health information and consents after account deletion30 years from the last attended class (§ 199(2) BGB), with processing restricted
Log of accesses to blocked recordsIndefinite — it has to outlive the records it documents, and contains no health data itself

12. Your rights

You have the following rights against us:

  • Access to the data stored about you (Art. 15 GDPR)
  • Rectification of inaccurate data, or completion of incomplete data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR), unless one of the grounds in Art. 17(3) GDPR applies — on the two cases where that is so here, see section 7
  • Restriction of processing (Art. 18 GDPR)
  • Data portability in a structured, commonly used, machine-readable format (Art. 20 GDPR)
  • Withdrawal of a consent at any time with effect for the future (Art. 7(3) GDPR). Withdrawal is as easy as giving consent: untick the box in the member form, or send us an email. The lawfulness of processing carried out before the withdrawal is unaffected.
  • Complaint to a data protection supervisory authority (Art. 77 GDPR)

To exercise these rights, use the contact details in section 1. We respond within one month.

Right to object under Art. 21 GDPR

Where we process your data on the basis of a legitimate interest under Art. 6(1)(f) GDPR, you have the right to object to that processing at any time on grounds relating to your particular situation. We will then stop processing the data unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

An objection in writing to the email address in section 1 is sufficient; giving reasons helps us weigh the matter but is not a condition of its effectiveness.

Competent supervisory authority

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit
Baden-Württemberg
Lautenschlagerstraße 20
70173 Stuttgart, Germany
Phone: +49 711 615541-0
Email: poststelle@lfdi.bwl.de
https://www.baden-wuerttemberg.datenschutz.de

Independently of this, you may also contact the supervisory authority where you live or work.

13. No automated decision-making

No automated individual decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. We do not evaluate you automatically, build no usage profiles, and use no advertising or analytics technologies.

14. Changes to this Privacy Policy

We update this policy when the processing it describes changes. The version published here at any given time governs; the date at the top states which version that is. Where a change affects a consent, we ask for it again and do not rely on the earlier one.

15. Language versions

This Privacy Policy is available in German, Spanish and English. Only the German version is legally binding.