Datasecurity Policy
for the website www.blindside.pro
ant the blindside-App

The purpose of this privacy policy is to inform you as a user about the collection of personal data on this website. The privacy policy for the blindside app can be found below.

A. RESPONSIBLE PARTY

The responsible party within the meaning of the General Data Protection Regulation (Art. 4 (7) DSGVO) and the other national data protection laws and data protection regulations is:
Blindside HB GmbH
Franz-Ehrlich-Straße12
12489
Berlinbenedikt.heinekamp@blindside.pro
Vollständige Provider ID: www.blindside.pro/impressum

These Contact details are thus relevant for all questions of a data protection nature regarding this website as well as for all data protection claims on your part.

B. COLLECTION AND STORAGE OF PERSONAL DATA WHEN VISITING OUR WEBSITE

In the following, we inform you about the processes relevant under data protection law that take place when you call up our website.

1. Log filesEvery time you call up our website, we automatically collect data and information from the computer system that you use to call up the website. The following data is collected:
(1) Information about your browser type and the version used
(2) Information about your operating system
(3) Information about your Internet service provider
(4) Date and time of your access
(5) Websites from which your system accesses our website
(6) Websites that are accessed by your system via our websiteThe data is stored in the log files of our system for 14 days. Not affected by this are your IP addresses or other data that allow the data to be assigned to you. A storage of this data together with other personal data of you does not take place. The legal basis for the temporary storage of this data is Art. 6 para. 1 lit. f DSGVO.
Both the collection of the data and the storage of the data in log files are mandatory for the provision and operation of our service. Therefore, there is no possibility for you to object.

2. CookiesWe use so-called "cookies" on our website. These are small files that are automatically created by your browser and stored on your computer system when you visit our site. Cookies do not cause any damage to your computer system and do not contain any viruses, Trojans or other malware.We use cookies to improve our website, for example, to make it more user-friendly and to adapt it to user interests.The following data is stored and transmitted in the cookies:
(1) language settings
(2) log-in information
(3) use of website functionsThe data collected in this way is pseudonymized by technical precautions.
Therefore, it is not possible to assign the data to you. The data is not stored together with any other personal data.The data processed by cookies.
Therefore, an assignment of the data to you is not possible. The data is not stored together with other personal data.The data processed by cookies is necessary for the aforementioned purposes to protect our legitimate interests as well as those of third parties in accordance with Art. 6 (1) p. 1 lit. f DSGVO.Most browsers accept cookies automatically. To prevent this, however, you can configure your browser so that no cookies are stored on your computer system or a notice always appears before a new cookie is created. However, the complete deactivation of cookies may mean that you cannot use all the functions of our website.

3. Website analysisOn this website, we use the "Google Analytics" service. This is a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.This service allows us to create pseudonymous usage profiles and to use cookies (see under B. 2.). The information generated by the cookie about your use of this website, such as
(1) browser type/version
(2) operating system used
(3) referrer URL (the previously visited page),
(4) time and country of the server requestare transmitted to a server of Google Inc. in the USA and stored there.
The information is used to evaluate the use of the website, to compile reports on website activity and to provide other services related to the use of the website and the Internet for the purposes of market research and demand-oriented design of these Internet pages.
This information may also be transferred to third parties if this is required by law or if third parties process this data on our behalf. Under no circumstances will your IP address be merged with other Google data. The IP addresses are anonymized so that an assignment is not possible.You can prevent the installation of cookies by selecting the appropriate settings on your browser software. You can also prevent the collection of data generated by the cookie and related to your use of the website, as well as the processing of this data by Google Inc. by downloading and installing a browser add-on (https://tools.google.com/dlpage/gaoptout?hl=de).
Further information on data protection in connection with Google Analytics can be found, for example, in the Google Analytics help (https://support.google.com/analytics/answer/6004245?hl=de). The cookies are stored for a period of 14 months.The use of Google Analytics is for the purpose of optimizing and evaluating our offer. The processing of the aforementioned data is necessary to protect our legitimate interest according to Art. 6 para. 1 lit. f DSGVO, i.e. the implementation of our business activities.You can prevent the collection of data (opt-out) via the following link: http://www.google.com/ads/preferences.

4. Marketing: Facebook Ads Conversion Tracking
We used an advertising measure of the Facebook network, the so-called "Facebook Pixel". This is operated by Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. This is a script ("pixel") that we use on our website. If you are logged in to the website of Facebook Ireland Ltd. at the same time as visiting our website, Facebook Ireland Ltd. can recognize that you have visited our website. This allows advertisements to be displayed on the network of Facebook Ireland Ltd. in a more targeted manner and thus more in line with your interests. It also allows us to track whether and which users were directed to our offer when they clicked on an ad in the Facebook Ireland Ltd. network.The purpose and scope of data collection and the further processing and use of the data by Facebook Ireland Ltd. as well as your rights in this regard and setting options for protecting your privacy can be found in the data protection information (www. facebook.com/about/privacy/) of Facebook Ireland Ltd. You can make your own settings regarding the advertisements on Facebook (https://www.facebook.com/settings?tab=ads).The use of this advertising measure by Facebook is necessary for the advertising of our offer and the optimization of the advertising measures in accordance with Art. 6 (1) lit. f DSGVO. Among others, you can prevent the collection of data (opt-out) via the following links to third-party sites: NAI - http://optout.networkadvertising.org/ or EDAA http://www.youronlinechoices.com/uk/your-ad-choices/.

5.Marketing: Branch.io tracking and deep linking
Branch Metrics, Inc., 1400 Seaport Blvd, Building B, 2nd Floor Redwood City, USA:We use the services of Branch.io for the following purposes:Branch offers deep linking solutions to provide the Blindside App with matching content in the app in a secure and reliable way, such as the achievement of a certain exercise if it was shared via external messaging services, for example. For this purpose, Branch collects certain device data. The data processing is based on your consent according to Art. 6 para. 1 p. 1 lit. a DSGVO as well as § 25 para. 1 TTDSG. Branch processes certain device data, especially in relation to the installation. In this way, we gain insights into the success of our app campaigns, and learn through which channel, via which platform and on the basis of which campaign the app installation took place. The legal basis for this is your consent according to Art. 6 para. 1 p. 1 lit. a DSGVO as well as § 25 para. 1 TTDSG.To ensure the improvement of the user experience, Branch.io collects in both cases: Operating system and version, timestamp, API key (identification key of the application), application version, device model, manufacturer and identification number, iOS identification key for advertising, iOS identification key for vendors, Android identification key for advertising, IP address and network status. The aforementioned data, in particular the IP address, is used solely for the purpose of establishing a link to Blindside content (/products) and only for a limited period of time. Branch.io may use cookies in the process. You can object to the collection of data by Branch.io at the following link: https://app.link/optout. Otherwise, you can find more information about Branch.io's privacy policy at https://branch.io/policies/#privacy.

6. Marketing & Technical Monitoring with Google Firebase
Firebase is a mobile and web application development platform developed in 2011 by Firebase, Inc. in San Francisco, USA. and acquired in 2014 by Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). Blindside uses Firebase in its app by analyzing user behavior within the apps. In doing so, anonymous activity data, i.e. touch gestures, scrolling or user interactions, are collected and stored. Only anonymized data is collected as part of the service and is not linked to the actual user data. Incidentally, you can find more information from Firebase at: https://firebase.google.com/support/faq/ and on data protection at: https://www.google.com/policies/privacy/.7. Marketing with Google Ads (Remarketing)Our app Internet presence also uses the remarketing function within the Google AdWords service. Google AdWords is an online advertising program of Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). With the remarketing function, we can present users of our app with advertisements based on their interests on other websites within the Google display network (on Google itself, so-called "Google Ads" or on other websites). For this purpose, the interaction of users with blindside ads is analyzed. If a potential user clicks on an ad but does not download the app, targeted ads for the download can be displayed. For this purpose, Google stores a number in the browsers of users who visit certain Google services or website in the Google display network. This number, known as a "cookie", is used to record the visits of these users. This number is used to uniquely identify a web browser on a particular computer and not to identify an individual. The information collected by the cookie about the use of our website (including your IP address) is usually transferred to a Google server in the USA and stored there.

We would like to point out that on this website Google AdWords (Remarketing) has been extended by the code "gat._anonymizeIp();" to ensure anonymized collection of IP addresses (so-called IP masking). At our instigation, your IP address is therefore only recorded by Google in shortened form, which ensures anonymization and does not allow any conclusions to be drawn about your identity. In the event that IP anonymization is activated on this website, your IP address will be truncated beforehand by Google within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. In addition, you can deactivate the interest-based ads on Google as well as interest-based Google ads on the web (within the Google display network) in your browser by clicking on the "deactivate" link under http://www.google.de/settings/ads in the "Deactivation settings" sub-item in each case. Furthermore, you can also deactivate interest-based advertising at http://www.networkadvertising.org/choices/?partnerId=1/ via opt-out, for which an opt-out cookie is set on your computer.8. User Experience and TrackingTo make the user experience as good as possible and to keep improving it, we record the behavior of users within the app. This means specifically, for example, to offer better suggestions for exercises, we log the activities of a user limited to categories (e.g. tags) of his behavior. However, the user remains unrecognized, because the software is not interested in personal data, but only in the behavior of an anonymous user.To be able to manage the tracking, we use services from AWS Germany, Amazon Web Services in Germany. This service is offered by Amazon Web Services, Inc, 410 Terry Avenue North, Seattle WA 98109, USA.

C. CONTACTING US

You may contact us electronically by e-mail or by filling out a form on the website. In this case, the data you send to us will be stored by us. This involves:(1) Your name(2) Date of contact(3) Your e-mail address(4) If applicable, further data if you provide itIf you write us an e-mail or use the form and are interested in our offers, the legal basis for data processing is Art. 6 (1) lit. b DSGVO. This data transmitted to us will only be used to carry out the conversation and will not be passed on to third parties.We will delete this data if it is not necessary for the respective purpose.
This data transmitted to us will only be used to carry out the conversation and will not be passed on to third parties.we will delete this data when it is no longer needed for the respective purpose. I.e., when the exchange by e-mail with you has ended and we have fully processed your request.You have the option to revoke your consent to the processing of your data at any time. To do so, please use the contact options mentioned above. In the event of a revocation, all your personal data stored for the purpose of contacting you will be deleted.

D. HOSTING

For hosting our website, the Blindside App we use servers of AWS Germany, Amazon Web Services in Germany. This service is provided by Amazon Web Services, Inc, 410 Terry Avenue North, Seattle WA 98109, USA. However, the data of visitors to the website and users of Blindside are only stored and processed in Germany.

E. REGISTRATION

To use the blindside service, you must create a user account with us. The data you provide in this process will only be used for the purposes of using the service. The data stored as part of the registration will not be disclosed to third parties and are used for the use of the service. The storage of the date of birth is necessary to ensure that the exercises are age-appropriate.During registration, the following data is stored:
(1) Your IP address
(2) Date and time of registration
(3) Your name
(4) Your e-mail address

Before sending the registration, your consent is obtained and reference is made to this privacy policy (Art. 6 para. 1 lit. a DSGVO).Deletion of the user account is possible at any time. However, any data from a contractual relationship is not covered by this.
(1) Payment transactionWe use payment service providers to carry out possible payment transactions. In addition to the payment data (your bank details for direct debit or your credit card details), the following data will also be processed by the payment provider you use:
(1) Your name
(2) Your address
(3) Your e-mail address
(4) IP address
The payment data provided and the other data will not be disclosed by us or the payment provider to third parties who are not involved in the performance of the contract and the processing of the payment (exception: credit agencies, see. The legal basis for the storage and processing of this data follows from Art. 6 para. 1 lit. b DSGVO. You can revoke your consent to the processing of your data at any time. To do so, please contact us using the contact options listed above. In the event of a revocation, all your personal data will be deleted, unless this conflicts with a statutory retention period.As payment providers can be used:

PayPal: This is a service of PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. Please note that PayPal Europe works with credit reporting agencies. It is therefore possible that your data will be transferred to the companies mentioned by PayPal Europe in their privacy policy. You can view PayPal's privacy policy here: https://www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=de_DE

ChargeBee: This is a payment service provided by ChargeBee Inc. Personal data processed: Email; last name; usage data; billing address; first name; payment data. You can view PayPal's privacy policy here: www.chargebee.com/privacy/

Stripe: Stripe is a payment service provided by Stripe Technology Europe Ltd, Processed personal data: Email; Last Name; Billing Address; First Name; Payment Data You can view Stripe's De Privacy Policy here: https://stripe.com/ie/privacy

F. PROCESSING IN THIRD COUNTRIES IN GENERAL

To the extent and unless otherwise indicated above, the processing of your personal data in countries outside the European Union (EU) or the European Economic Area (EEA) is carried out exclusively on the basis of the legal requirements pursuant to Art. 44 DSGVO. In the present case, this is exclusively the case either on the basis of an adequacy decision of the European Commission (Art. 45 DSGVO) and/or on the basis of appropriate safeguards (Art. 46 DSGVO).

G. GENERAL STORAGE PERIOD

In general, personal data will be stored exclusively for as long as necessary to fulfill the purpose of the data collection or to comply with the respective legal retention period. After the purpose ceases to exist or the period expires, the data is deleted.H. DATA SUBJECT RIGHTSSo far as we have processed personal data of you, you are a data subject in the sense of the GDPR and you are entitled to the following rights against us:

(1) Art. 15 GDPR - You may request information about your personal data processed by us. In particular, you can request information about the processing purposes, the category of personal data, the categories of recipients to whom your data have been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right of complaint, the origin of your data if it has not been collected by us, as well as the existence of automated decision-making including profiling and, if applicable. (2) Art. 16 DSGVO - You may request the correction of inaccurate or incomplete personal data stored by us without undue delay.(3) Art. 17 DSGVO - You can request information about your personal data processed by us. In particular, you can request information about the processing purposes, the category of personal data, the categories of recipients to whom your data have been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right of complaint, the origin of your data if it was not collected by us, as well as the existence of automated decision-making, including profiling, and, if applicable, meaningful information about its details.
(2) Art. 16 DSGVO - You may request without undue delay the rectification of inaccurate or incomplete personal data stored by us.

(3) Art. 17 DSGVO - You may request the erasure of your personal data stored by us, unless the processing is necessary for the exercise of the right to freedom of expression and information, for compliance with a legal obligation, for reasons of public interest or for the establishment, exercise or defense of legal claims.

(4) Art. 18 DSGVO - You may request the restriction of the processing of your personal data - insofar as the accuracy of the data is disputed by you, - insofar as the processing is unlawful, but you object to its erasure and we no longer need the data, but you need it for the assertion, exercise or defense of legal claims - or insofar as you object to the processing pursuant to Art. 21 DSGVO objected to the processing.Art. 20 DSGVO - You may receive your personal data that you have provided to us in a structured, common and machine-readable format or request the transfer to another controller.Art. 7 (3) DSGVO - You may revoke your consent once given to us at any time. This has the consequence that we may no longer continue the data processing based on this consent in the future.Art. 77 DSGVO - You may complain to a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or our registered office for this purpose.

(5) Art. 20 DSGVO - You may receive your personal data that you have provided to us in a structured, common and machine-readable format or request that it be transferred to another controller.

(6) Art. 7 (3) DSGVO - You may revoke your consent once given to us at any time. This has the consequence that we may no longer continue the data processing based on this consent in the future.(7) Art. 77 DSGVO - You may complain to a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or our registered office for this purpose.(5) Art. 20 DSGVO - You can receive your personal data that you have provided to us in a structured, common and machine-readable format or request the transfer to another controller.(6) Art. 7 (3) DSGVO - You can revoke your consent once given to us at any time. This has the consequence that we may no longer continue the data processing based on this consent in the future.

(7) Art. 77 DSGVO - You may complain to a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or our registered office for this purpose.I. RIGHT OF OBJECTIONIf your personal data is processed on the basis of legitimate interests pursuant to Art. 6 (1) p. 1 lit. f DSGVO, you have the right to object to the processing of your personal data pursuant to Art. 21 DSGVO, provided that there are grounds for doing so that arise from your particular situation or the objection is directed against direct advertising. In the latter case, you have a general right of objection, which will be implemented by us without specifying a particular situation.If you wish to exercise your right of revocation or objection, an e-mail to the above e-mail address is sufficient.Data protection notice for the app blindsideIn the following, we provide information about the processing of users' data when they use the app.

1. Person responsibleName and contact details of the person responsible for processing: Blindside HB GmbH, Franz-Ehrlich-Strasse 12, 12489 Berlin. Further contact details at: www.blindside.pro/impressum

2. Scope of data processingWe process personal data provided by the user under this contract for the intended purpose and in accordance with the statutory provisions. For the purpose of using the app, we store the following data of the users- Name and email address- Technical information for the detection and prevention of error causes (operating system version, system language, crash logs, error messages, etc.)- as well as other data if these are provided voluntarily by the users in the context of using the appThis processing is carried out for the purpose of fulfilling the usage contract in accordance with Art. 6 (1) lit. b DSGVO.The data is stored until the user deletes his account or asserts his right to deletion under data protection law. 3 Application AnalysisOn the blindside app we use the service "Google Analytics". This is a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.This service enables us to create pseudonymized usage profiles and to use cookies (see under B. 2.). The information generated by the cookie about your use of the blindside app, such as
(1) operating system used
(2) time and country of server requestsare transmitted to a server of Google Inc. in the USA and stored there.
The information is used to evaluate the use of the website, to compile reports on website activity and to provide other services related to website and internet use for the purposes of market research and demand-oriented design of this app. This information may also be transferred to third parties if this is required by law or if third parties process this data on our behalf. By installing the blindside app, you consent to the installation of the cookies necessary for the purposes just described.  Further information on data protection in connection with Google Analytics can be found, for example, in the Google Analytics help (https://support.google.com/analytics/answer/6004245?hl=de). The cookies are stored for a period of 14 months.
The use of Google Analytics is for the purpose of optimizing and evaluating our offer. The processing of the aforementioned data is necessary to protect our legitimate interest according to Art. 6 (1) lit. f DSGVO, i.e. the performance of our business activities.You can prevent the collection of data (opt-out) via the following link: http://www.google.com/ads/preferences.Neben Google Analytics, we also use the Smartlook service of Smartsupp.com, s.r.o., Lidická 2030/20, 602 00 Brno, Czech Republic.
This service enables qualitative analysis of visitor behavior in the app. Smartlook achieves this by collecting user data using a Javascript snippet, which is integrated directly into the master file and which records the user navigation on in the app partly also by video and subsequently presents it visually for us as the app operator.The data collected when using Smartlook cannot be assigned to any specific user. The website operator can only track how the user moves, where clicked and how far scrolled. Furthermore, the screen size of the device, the device type, information about the operating system, the country from which was accessed and the preferred language are recorded. If personal data of visitors or third parties are displayed on the website, these are automatically hidden by Smartlook. Smartlook stores the records on the Amazon Web Service Cloud of the American company Amazon and deletes them after 30 days according to its own information. The services of Smartlook can thus include a cross-border data exchange, in particular to U.S. authorities, due to the U.S. Patriot Act 2001 or the EU-US Privacy Shield (EU-US Privacy Shield).

For the identification of the user cookies can be used to identify the user. Personal data are not stored in the cookies according to Smartlook.Insofar as the data processing for the purposes described above with the consent of website visitors, the legal basis is Article 6 paragraph 1 a) DSGVO (consent). Otherwise, the data processing is based on Article 6 paragraph 1 f) DSGVO ("legitimate interests"), whereby the legitimate interests lie in a technically flawless online offering and its economically-efficient design and optimization.The detailed privacy policy of Smartlook visitors can find here: https://help.smartlook.com/en/articles/3244452-privacyWiderruf/ Objection/ Settings:- The Smartlook service can be deactivated using the opt-out switch at: Smartlook Opt-Out be deactivated.- The setting of cookies can be prevented in accordance with the explanations in the Cookies section of this privacy policy.

4. Disclosure of dataPersonal data will be treated by us as strictly confidential and will not be disclosed to third parties, unless there is express consent of the users. An exception applies if this is necessary in the context of contract performance or if there is a legitimate interest.

5. Data protection claimsUsers have the right- to request information about their personal data processed by us in accordance with Art. 15 DSGVO;- to request the correction of incorrect or completion of their personal data stored by us without delay in accordance with Art. 16 DSGVO;- to request the deletion of their personal data in accordance with Art. 17 DSGVO to request the deletion of your personal data stored by us as soon as the license agreement has been terminated;- in accordance with Art. 18 DSGVO to request the restriction of the processing of your personal data;- in accordance with Art. 20 DSGVO to receive your personal data that you have provided to us in a structured, common and machine-readable format or to request the transfer to another controller;- in accordance with Art. 7 (3) DSGVO to revoke your consent once given to us at any time. This has the consequence that we may no longer continue the data processing based on this consent in the future and- to complain to a supervisory authority in accordance with Art. 77 DSGVO. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or our company headquarters for this purpose. If your personal data is processed on the basis of legitimate interests pursuant to Art. 6 (1) p. 1 lit. f DSGVO, you have the right to object to the processing of your personal data pursuant to Art. 21 DSGVO, provided that there are grounds for doing so that arise from your particular situation or the objection is directed against direct advertising. In the latter case, you have a general right of objection, which is implemented by us without specifying a particular situation.