Privacy Policy
1. Controller
The controller responsible for processing your personal data in connection with NexoWOD is:
NexoWOD eine Marke von:
Rene Kopplin
codevale web & it
Am Bautzenwald 10/1
74229 Oedheim / DE
Email: contact@codevale.de
2. Types of data processed
We process in particular the following categories of personal data, insofar as you provide them to us when using NexoWOD or they arise technically:
- Basic data (e.g. first and last name, email address, password hash, support code)
- Authentication data for passkeys/WebAuthn (if enabled): credential ID, public key and technical metadata (e.g., AAGUID/authenticator type, last-used timestamps). We do not process or store biometric data (e.g., fingerprint/Face ID); verification happens locally on your device via the operating system/browser.
- Contract and membership data (e.g. box affiliation, memberships, pricing plans, training plans)
- Usage data (e.g. logins, booked classes, check-ins, messages in the box community chat, posts/comments/reactions in the community feed, support communication)
- Technical data (e.g. IP address, browser type, operating system, timestamps, device information)
- When using the Android app, additionally app and device information (e.g. app version, push token, Android permission status), an optionally selected Android calendar, and optionally shared Health Connect data (e.g. steps, distance, calories, heart rate, workout and body measurement data).
- Billing and payment data where necessary (e.g. information on booked plans; payment processing is usually carried out via external payment providers).
3. Purposes of processing and legal bases
We process your personal data for the following purposes in accordance with Art. 6 GDPR:
- Provision and operation of the NexoWOD platform, user account management and authentication (Art. 6(1)(b) GDPR – performance of a contract).
- Optional passwordless sign-in via passkeys/WebAuthn (Art. 6(1)(b) GDPR – performance of a contract; additionally Art. 6(1)(f) GDPR – legitimate interest in secure authentication).
- Organisation and administration of classes, memberships, training plans and box management (Art. 6(1)(b) GDPR).
- Communication within the box community (chat, community feed, notifications), support requests and service communication (Art. 6(1)(b) and (f) GDPR).
- System security, error analysis, abuse and fraud detection (Art. 6(1)(f) GDPR – legitimate interest in secure and stable operation).
- Provision of optional native Android app features such as push notifications, calendar integration and Health Connect (Art. 6(1)(a) and (b) GDPR; for health data additionally your explicit consent under Art. 9(2)(a) GDPR).
- Compliance with legal obligations (e.g. commercial and tax retention obligations) (Art. 6(1)(c) GDPR).
Where we ask for your consent in individual cases (e.g. for optional marketing emails or certain cookies), processing is based on Art. 6(1)(a) GDPR. You may withdraw any consent given at any time with effect for the future.
For new registrations, an additional optional consent for WhatsApp marketing may be collected (explicit checkbox/opt-in). Only if you actively select this option do we process your WhatsApp contact data and consent status to send WhatsApp messages via the WhatsApp Business Platform (Meta). The legal basis is Art. 6(1)(a) GDPR; consent can be withdrawn at any time with effect for the future.
Cookies & consent management: we use technically necessary cookies for operation, security, language preferences and session management. In addition, and only with your explicit consent, we may use Google Analytics 4 to analyze reach, usage and technical website performance. The legal basis is Art. 6(1)(a) GDPR.
If you consent in the cookie settings, cookies such as `_ga` and similar identifiers may be used and usage data (e.g. pages visited, approximate region, technical browser/device information and a shortened IP address) may be transmitted to Google. Recipients of analytics data include Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and, as part of intra-group processing, Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. You can withdraw or change your consent at any time with effect for the future using the cookie settings below. We will ask for this consent again after 12 months at the latest.
4. Community features (feed, direct messages, friends, leaderboard & push)
We process data to provide community features: the community feed with posts, comments, reactions, fistbumps and optional image/profile media, direct messages between members, friend relationships, leaderboard display and push notifications.
- Data categories: feed content and metadata (posts, comments, reactions, fistbumps, timestamps and relationship/visibility context), optionally uploaded feed images and shared profile media in the feed, DM content and metadata (sender/recipient, timestamps, read status), friend relationships, leaderboard data (name/profile and scores), push subscription (endpoint/keys).
- Legal basis: legitimate interests (Art. 6(1)(f) GDPR) for community features; right to object. Where you actively create feed posts, comments or uploads, processing also takes place to provide the requested feature / perform the usage contract (Art. 6(1)(b) GDPR). Push notifications based on consent (opt‑in), revocable at any time.
- Retention: feed posts, comments, reactions and fistbumps are generally stored until you delete them, the underlying relationship/function no longer applies, or your account is deleted, unless statutory retention obligations apply. Read direct messages are typically deleted automatically after 14 days. Unread messages are retained until read. Friend links until revoked/removed; leaderboard data until opt‑out or account deletion; push subscriptions until revocation or inactivity.
- Security: transport encryption (TLS) and server‑side encryption of stored direct messages (AES‑256‑GCM). Not end‑to‑end encrypted.
- Visibility & opt‑outs: the community feed is visible only to authorized users within the community/friends feature; feed content, comments and reactions are visible to users who are allowed to see the relevant post within the app. Leaderboards are visible to members of the respective box; anonymous display/opt‑out is possible. Direct messages are visible only to the participants; reachability can be limited (e.g., friends only). Push opt‑in can be revoked at any time.
5. Android app, Google Play, calendar & Health Connect
In addition to browser-based use, we also provide NexoWOD as an Android app. The app loads the NexoWOD platform in a secured WebView and augments it with native Android features. This results in additional technical app and device information, in particular app version, permission status, push token and, where applicable, selected local settings on the device.
- Google Play: during download, updates and distribution of the Android app, Google as operator of the Google Play Store processes its own technical data. We have only limited influence over this processing; Google's privacy information applies in addition.
- Android push: if you enable push notifications in the Android app, a device-specific Firebase token is processed and transmitted to our servers so notifications can be delivered to your device. The legal basis is your consent (Art. 6(1)(a) GDPR).
- Android calendar: if you enable calendar access, the app reads the calendars available on the device and stores the selected target calendar. Booked classes can then be written directly to the selected Android calendar. The legal basis is your consent or your request to use this feature (Art. 6(1)(a) and (b) GDPR).
- Health Connect: if you connect Health Connect and grant the relevant permissions, NexoWOD reads the health and workout data you have shared directly on the device. Depending on your permissions, this may in particular include steps, distance, active and total calories, exercise sessions, heart rate, weight and body fat. This processing takes place exclusively on the basis of your explicit consent (Art. 6(1)(a) in conjunction with Art. 9(2)(a) GDPR).
- Withdrawal & control: you can revoke Android permissions for push, calendar and Health Connect at any time in the app or in Android system settings. Already stored push devices can be removed in your profile; local calendar entries and Health Connect permissions can additionally be managed directly on your device.
6. Recipients of the data
We only transfer your personal data to third parties where this is necessary for the purposes mentioned, there is a legal obligation or you have given your consent. Possible categories of recipients in particular are:
- Box owners and coaches, insofar as this is necessary to manage your membership and conduct classes.
- IT service providers and hosting/storage providers (in particular Hetzner Online GmbH) that we use to operate our root servers and store image files (e.g. avatars, box and chat images).
- Content Delivery Network (CDN) BunnyCDN (BunnyWay d.o.o.) for delivering and caching image files to improve load times and availability. In doing so, technically necessary access data (e.g., requested URL, timestamp, user agent, and an anonymized/truncated IP address) may be processed. We use EU-only locations; server logs are disabled (no persistent storage of access logs).
- Web analytics with Google Analytics 4, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The data recipient is Google Ireland Limited; as part of service provision, Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, may also access the data.
- Google Ireland Limited / Google LLC insofar as this is technically necessary for distributing the Android app via Google Play and for Android push notifications via Firebase Cloud Messaging.
- YouTube / Google Ireland Limited / Google LLC insofar as embedded YouTube videos in the members stream are loaded via the youtube-nocookie.com domain. When the player is loaded, your IP address, browser/device information and usage data may in particular be transmitted to YouTube or Google.
- Meta Platforms Ireland Limited / Meta Platforms, Inc., where you explicitly consent to WhatsApp marketing during a new registration. In this case, WhatsApp contact data and message metadata required for delivery are processed via the WhatsApp Business Platform.
- Payment service providers if you use paid services.
- The payment service provider Stripe (Stripe Payments Europe Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland) for processing payments (e.g. membership fees, bookings). In this context, identification, contract and payment data are transmitted to Stripe insofar as this is necessary to carry out the transaction. Further information on data processing by Stripe can be found in Stripe's privacy policy at https://stripe.com/privacy.
- Advisors (e.g. tax advisors), where necessary.
7. Map services & geocoding (OpenStreetMap)
We use OpenStreetMap (OSM) data for map rendering and geocoding features (e.g., showing box locations, radius search, directions).
- GDPR-compliant: map tiles and the map viewer are self-hosted in the EU/EEA (e.g., on our own infrastructure/Hetzner). No third-party cookies or tracking scripts are loaded.
- Geocoding: requests are preferably routed via infrastructure we control. If, for technical reasons, OSM infrastructure is used, we only transmit the search terms necessary for geocoding (e.g., city/address). No personal usage profiles are created.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in convenient location search and displaying training venues). If you enter an address for concrete directions, processing may also serve contract performance or pre-contractual steps (Art. 6(1)(b) GDPR).
- Retention: technical logs to ensure operation (e.g., error messages) are stored only briefly and then deleted or anonymized.
8. Web-push notifications
If you enable push notifications, a device-specific token (endpoint) is stored to send messages to your device. Legal basis is your consent (Art. 6(1)(a) GDPR). You may withdraw consent at any time in settings or via browser/system settings.
9. Data transfers to third countries
Processing and storage of your data currently take place exclusively on servers located within the European Union. For this purpose, we use, among other things, root servers and storage solutions provided by Hetzner Online GmbH (Germany). As a rule, no transfers to third countries (outside the EU/EEA) take place unless this is expressly stated in this privacy policy or required by law.
Where we use the payment service provider Stripe, personal data may be transferred to the USA. Stripe relies, among other things, on the EU-US Data Privacy Framework and on appropriate safeguards within the meaning of Art. 44 et seq. GDPR (e.g. EU standard contractual clauses). Further information can be found in Stripe's data protection information. We ensure that only the data strictly necessary for processing the payment are transmitted.
Where Google Analytics 4 is used, personal data may also be transferred to the USA. This transfer takes place on the basis of the EU-US Data Privacy Framework, provided that Google LLC is appropriately certified. In addition, where necessary, other appropriate safeguards pursuant to Art. 44 et seq. GDPR may be agreed.
When using the Android app, data may also be transferred to Google companies in connection with Google Play and Firebase Cloud Messaging. Where recipients in the USA are involved, this is based on the EU-US Data Privacy Framework or supplementary appropriate safeguards pursuant to Art. 44 et seq. GDPR.
If you explicitly enable WhatsApp marketing during a new registration, data may also be transferred to Meta companies via the WhatsApp Business Platform. Where recipients in the USA are involved, transfers are based on the EU-US Data Privacy Framework or supplementary appropriate safeguards under Art. 44 et seq. GDPR.
If you access embedded YouTube videos in the members stream, content from YouTube is loaded via youtube-nocookie.com. In this context, personal data may also be transferred to Google companies and therefore to the USA. This processing only takes place in connection with loading the embedded video.
10. Retention period
We store your personal data only for as long as is necessary for the purposes mentioned or where statutory retention obligations exist. Chat messages are generally deleted automatically after a maximum of 7 days. Contract and billing data are retained in accordance with statutory periods (in particular under commercial and tax law).
Security and error analysis logs (e.g., server logs) are generally retained between 7 and 30 days and then deleted or anonymized. Backups may be retained for up to 30 days for technical reasons; productive access occurs only for restoration purposes.
Passkeys/WebAuthn: we store your registered passkey credentials (credential ID/public key) until you remove them in your account or delete your account. Technical metadata (e.g., last use) is used for account security and troubleshooting and is kept only as long as necessary for those purposes.
We store Google Analytics data only for as long as necessary for reach analysis, technical evaluation and comparison periods. Unless compelling reasons require otherwise, we follow the retention periods configured in Google Analytics; user and event data there is generally deleted or anonymized after 2 and at most 14 months. Your consent decision is stored for 12 months; after that we request your consent again.
11. Your rights
Within the framework of the applicable legal provisions, you have the following rights at any time:
- Access to the personal data we hold about you (Art. 15 GDPR).
- Rectification of inaccurate data or completion of incomplete data (Art. 16 GDPR).
- Erasure of your data (Art. 17 GDPR) where no statutory retention obligations oppose this.
- Restriction of processing (Art. 18 GDPR).
- Objection to the processing of personal data (Art. 21 GDPR) where processing is based on legitimate interests pursuant to Art. 6(1)(f) GDPR.
- Data portability (Art. 20 GDPR), where processing is based on your consent or a contract and carried out by automated means.
To exercise your rights, you may contact us at any time using the contact details given above. You also have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR.
12. Obligation to provide data
Providing certain personal data is necessary in order to use NexoWOD and to conclude or perform memberships and class bookings. Without this data, the platform can only be used to a limited extent or not at all. Providing data for optional features (e.g. certain profile details or marketing communication) is voluntary.
Passkeys/WebAuthn are optional. If you do not want to use passkeys, you can continue to sign in with email/password.
Children/minors: where you add profiles for children, we process only minimal data (e.g. name, date of birth) to manage classes. Processing takes place within the membership framework by legal guardians.
13. Cookies and tracking technologies
NexoWOD uses cookies and similar technologies to enable the use of the website and app, maintain sessions and provide certain features (e.g. login status, preferred language).
Where these cookies are technically necessary for operation, processing is based on Art. 6(1)(f) GDPR. For non-essential cookies (e.g. statistics or marketing cookies), where used, we obtain your prior consent (Art. 6(1)(a) GDPR). Where Google Analytics is used, it is a statistics/analytics technology provided by Google Ireland Limited; Google LLC in the USA may also be a recipient. Further details on the cookies used, recipients, retention periods and your options can be found in our cookie notice or the relevant settings area.
Embedded YouTube videos in the members stream use enhanced privacy mode via youtube-nocookie.com where possible. Nevertheless, YouTube may access device information or use similar technologies when the player is loaded or during playback, which is outside our full control.
14. Changes to this privacy policy
We reserve the right to update this privacy policy where necessary, in particular if we introduce new features or if legal or regulatory requirements change. The current version is always available in the app or on the website.