Language

We are delighted that you are visiting our website hk.gymaesthetics.com and are interested in our company. We attach a great deal of importance to protecting your personal data. Personal data is information about an identified or identifiable natural person’s personal or factual circumstances. This includes details such as the person’s real name, address, phone number and date of birth, as well as all other data which may refer to an identifiable person.
Because personal data is afforded special legal protection, we only collect it insofar as doing so is necessary to making our website available and providing our service. Below, we have provided an outline of what personal information we collect about you during your visit to our website and how we use it.
Our data protection practices comply with legal regulations, particularly those set down in the German Federal Data Protection Act (BDSG), the German Telemedia Act (TMG) and the EU’s General Data Protection Regulation (GDPR). We will only collect, process and store your personal data insofar as doing so is necessary to making this website and our contents and services functionally available, as well as for the purpose of processing enquiries and, if necessary, handling orders / contracts, but only if there is a legitimate interest for doing so under the terms of Art. 6, Para. 1, Clause 1, lit. f of the GDPR or other statutory permission. Your data will also be used for further purposes precisely defined in your consent, e.g. to send advertising information by newsletter, only if you have separately given your consent beforehand.

1. Controller under the terms of Art. 4, Para. 7 of the GDPR

The controller under the terms of the GDPR, other national data protection legislation of the member states and other provisions under data protection legislation is:

Gym Aesthetics Sportsleish Limited
Flat F, 35/F, Montery Plaza
15 Chong Yip Street, Kwun Tong, HK

Email: service.hk@gymaesthetics.com
Tel.: 852 36203433

2. Providing the website and creating log files

Each time our website is accessed, our system automatically records data and information from the accessing computer’s computer system. The following data is collected in this regard:

Extent of data processing

(1) Information about the browser type and the version used
(2) The accessing device’s operating system
(3) The accessing device’s IP address
(4) Date and time of access
(5) Websites and resources (images, files, other page contents) which were accessed on our website
(6) Websites from which the user’s system accessed our website (referrer tracking)

This data is stored in our system’s log files. This data is not stored together with personal data belonging to a specific user, so individual site visitors are not identified.

  • Legal basis for personal data processing

Art. 6, Para. 1, lit. f of the GDPR (legitimate interest). Our legitimate interest is to guarantee achievement of the purpose outlined below.

  • Purpose of data processing

Logging is carried out to maintain our website’s compatibility for all visitors where possible and to combat misuse and eliminate faults. To this end, it is necessary to log the accessing computer’s technical data, so that we can respond to display errors, attacks on our IT systems and/or functionality errors on our website as early as possible. Additionally, we also use the data to optimise the website and to ensure the general security of our IT systems.

  • Duration of storage

The above technical data is deleted as soon as it is no longer needed to guarantee the website’s compatibility for all visitors, but at the latest within three months of our website being accessed.

  • Opportunity to object and remove

The opportunities to object and remove are based on the general regulations on the right of objection and claim for deletion under data protection legislation which are outlined below in this privacy policy.

3. Special features of the website

Our site offers you a variety of features which, when used by us, serve to collect, process and store personal data. We have provided an explanation of what happens to this data below:

  • Form for subscribing to the newsletter:
    • Extent of personal data processing

The data you entered when subscribing to the newsletter.

    • Legal basis for personal data processing

Art. 6, Para. 1, lit. a of the GDPR (implicit consent)

    • Purpose of data processing

Data captured on our newsletter’s sign-up screen is used by us for the sole purpose of sending our newsletter, in which we provide information about all our services and our news. Once you have signed up, we will send you a confirmation email containing a link you have to click on to complete the process of signing up to our newsletter (double opt-in).

    • Duration of storage

You can unsubscribe from our newsletter at any time by clicking on the Unsubscribe link, which is also included in every newsletter. We will delete your data immediately after you cancel your subscription. We will also delete your data immediately if you do not complete the sign-up process. We reserve the right to delete the same without any need to provide justification or to provide any prior or subsequent information.

    • Opportunity to object and remove

The opportunities to object and remove are based on the general regulations on the right of objection and claim for deletion under data protection legislation which are outlined below in this privacy policy.

  • Contact form(s):
    • Extent of personal data processing

The data you entered in our contact forms.

    • Legal basis for personal data processing

Art. 6, Para. 1, lit. a of the GDPR (implicit consent)

    • Purpose of data processing

We will use the data captured by means of our contact form(s) only to process the specific contact request received through the contact form(s).

    • Duration of storage

The data captured is deleted immediately after your request has been processed, provided that there are no statutory retention periods.

    • Opportunity to object and remove

The opportunities to object and remove are based on the general regulations on the right of objection and claim for deletion under data protection legislation which are outlined below in this privacy policy.

  • Login area:
    • Extent of personal data processing

The registration and login data you entered on our site.

    • Legal basis for personal data processing

Art. 6, Para. 1, lit. a of the GDPR (implicit consent)

    • Purpose of data processing

You can use a separate login area on our website. If you have forgotten your password or username for this area, you can request to have this data sent to you again after firstly entering your contact details (email address). Any usage data incoming within the context of using the login area is collected, saved and processed by us for the sole purpose of tackling misuse, troubleshooting and maintaining functionality. This data is not used for any other purposes or transferred to third parties.

    • Duration of storage

Data collected within the context of the ‘Forgotten your username or password?’ function is only used to re-send forgotten login data.

    • Opportunity to object and remove

The opportunities to object and remove are based on the general regulations on the right of objection and claim for deletion under data protection legislation which are outlined below in this privacy policy.

4. Automatic credit check / scoring

If we deliver any goods or services prior to receiving payment, we reserve the right to obtain an automatic credit report based on mathematical / statistical methods from the following company (companies) so as to protect our legitimate interests. We receive information from the following service provider regarding the statistical probability of default. The credit report may include probability values (score values), which are calculated based on scientifically recognised mathematical / statistical methods. Conclusions are thereby drawn as to the customer’s future risk of payment default using a wide range of features, such as income, address data, occupation, marital status and previous payment history. The result is expressed in the form of a payment value (“score”). The information obtained in this way forms the basis of our decision on whether to establish, execute or terminate a contractual relationship. However, selection of one of the payment methods offered does not depend on such information. The opportunities to object and remove are based on the general regulations on the right of objection and claim for deletion under data protection legislation which are outlined below in this privacy policy. Specific details:

  • Automatic identity and credit check when the “PayPal” payment method is selected:
    • Extent of personal data processing

If you have selected “PayPal” as your chosen payment method, we will forward your personal customer data collected within the context of the order process to PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter referred to as “PayPal”) within the context of payment handling. If you give your consent, the following data is affected by the data transfer: First name and surname, street, house number, postcode, town / city, date of birth, phone number and the data provided in connection with your order.

    • Legal basis for personal data processing

Art. 6, Para. 1, lit. b of the GDPR (implementation of pre-contractual measures)

    • Purpose of data processing

PayPal performs a credit check when you select “PayPal” as the payment method. During this process, mathematical and statistical procedures are used to calculate a rating with respect to the probability of default (calculate a so-called scoring value). PayPal uses the calculated scoring value as the basis for its decision on whether or not to provide the respective payment methods. A scoring value is calculated according to recognised scientific procedures. Reference is also made to the PayPal privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full

    • Duration of storage

We will store the relevant data for processing the payment as long as doing so is necessary for the execution of the transaction. If the data is subject to the legal retention requirements, deletion shall take place once the retention requirement has expired. The duration of PayPal’s data storage is determined by PayPal’s privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full

    • Opportunity to object and remove

The opportunities to object and remove are based on the general regulations on the right of objection and claim for deletion under data protection legislation which are outlined below in this privacy policy.

5. Statistical evaluation of visits to this website – web trackers

When this website or individual files on the website is / are accessed, we collect, process and store the following data: IP address, web page from which the file was retrieved, name of the file, the retrieval date and time, the data volume transmitted and the retrieval success notification (so-called web log). We only use this access data in a non-personalised form with a view to continuously improving our website and for statistical purposes.
We also use the following web trackers to evaluate visits to our website:

  • Google Ad Services / Google AdWords Conversion / Google Dynamic Remarketing

We use a web tracking service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter referred to as “Google Ad Services / Google AdWords Conversion / Google Dynamic Remarketing”) on our website. In the context of web tracking, Google Ad Services / Google AdWords Conversion / Google Dynamic Remarketing uses cookies, which are stored on your computer and enable analysis of the use of our website and your surfing behaviour (so-called tracking). We carry out this analysis based on the Google Ad Services / Google AdWords Conversion / Google Dynamic Remarketing tracking service in order to continuously optimise our website and improve its availability. In the context of using our website, data, including your IP address and user activities in particular, is sent to Google Ad Services / Google AdWords Conversion / Google Dynamic Remarketing servers and is processed and stored outside of the European Union, e.g. in the US. The legal basis for data processing is Art. 6, Para. 1, lit. a of the GDPR. Google Ad Services / Google AdWords Conversion / Google Dynamic Remarketing has certified itself in the context of the EU/US Privacy Shield Agreement (cf. https://www.privacyshield.gov/list). The data is deleted as soon as the purpose of its collection has been fulfilled. You will find further information about how the transferred data is handled in the Google Ad Services / Google AdWords Conversion / Google Dynamic Remarketing privacy policy: https://www.google.de/intl/de/policies/privacy/. You can prevent personal data (particularly your IP address) from being collected and disclosed and processing of this data by deactivating the execution of script codes in your browser, by installing a script blocker in your browser (which you will find at www.noscript.net or www.ghostery.com, for example) or by enabling your browser’s “Do Not Track” setting.

  • Google AdSense

We use a web tracking service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter referred to as “Google AdSense”) on our website. In the context of web tracking, Google AdSense uses cookies, which are stored on your computer and enable analysis of the use of our website and your surfing behaviour (so-called tracking). We carry out this analysis based on the Google AdSense tracking service in order to continuously optimise our website and improve its availability. In the context of using our website, data, including your IP address and user activities in particular, is sent to Google AdSense servers and is processed and stored outside of the European Union, e.g. in the US. The legal basis for data processing is Art. 6, Para. 1, lit. a of the GDPR. Google AdSense has certified itself in the context of the EU/US Privacy Shield Agreement (cf. https://www.privacyshield.gov/list). The data is deleted as soon as the purpose of its collection has been fulfilled. You will find further information about how the transferred data is handled in the Google AdSense privacy policy: https://www.google.de/intl/de/policies/privacy/. You can prevent personal data (particularly your IP address) from being collected and disclosed and processing of this data by deactivating the execution of script codes in your browser, by installing a script blocker in your browser (which you will find at www.noscript.net or www.ghostery.com, for example) or by enabling your browser’s “Do Not Track” setting.

  • Google Analytics
    • Extent of personal data processing

We use the web tracking service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter referred to as “Google Analytics”) on our site. In the context of web tracking, Google Analytics uses cookies, which are stored on your computer and enable analysis of the use of our website and your surfing behaviour (so-called tracking). We carry out this analysis based on the Google Analytics tracking service in order to continuously optimise our website and improve its availability. In the context of using our website, data, including your IP address and user activities in particular, is sent to Google LLC servers and is processed and stored outside of the European Union, e.g. in the US.
The European Commission has noted that an appropriate data protection level can exist in the US if the data processing company is subject to the EU/US Privacy Shield Agreement and if the data export to the US was designed to be permissible in this way. Google will anonymise your IP address before transmission if you activate IP anonymisation within this website’s Google Analytics tracking code. This website uses a Google Analytics tracking code expanded to include the gat._anonymizeIp(); operator so as to enable only anonymised collection of IP addresses (so-called IP masking).

    • Legal basis for personal data processing

Art. 6, Para. 1, lit. a of the GDPR (consent), either in the context of registration with Google (opening a Google account and accepting the privacy notice implemented there) or, if you have not registered with Google, through explicit consent when you call up our site.

    • Purpose of data processing

On our behalf, Google will use this information for the purpose of evaluating your visit to this website, compiling reports on website activities and providing us with other services relating to website and Internet use. The IP address transmitted by your browser in the context of Google Analytics is not associated with the other data held by Google LLC.

    • Duration of storage

Personalized data will be deleted or anonymized after a period of 14months.

    • Opportunity to object and remove

You can prevent personal data (particularly your IP address) from being collected and disclosed to Google and Google’s processing of this data by deactivating the execution of script codes in your browser, by installing a script blocker in your browser (which you will find atwww.noscript.net or www.ghostery.com, for example) or by enabling your browser’s “Do Not Track” setting. Furthermore, you can prevent Google’s collection and processing of the data generated by the Google cookie and related to your use of the website (including your IP address) by downloading and installing the browser plugin available at the following link (http://tools.google.com/dlpage/gaoptout?hl=de). You can find Google Analytics’ security and privacy policy at http://www.google.com/intl/de/analytics/learn/privacy.html

Click here to opt-out of the Google Analytics tracking.

  • Facebook Connect / Login

We use a web tracking service provided by Facebook, Inc., 1601 Willow Road, Menlo Park, CA 94024, USA (hereinafter referred to as “Facebook Connect / Login”) on our website. In the context of web tracking, Facebook Connect / Login uses cookies, which are stored on your computer and enable analysis of the use of our website and your surfing behaviour (so-called tracking). We carry out this analysis based on the Facebook Connect / Login tracking service in order to continuously optimise our website and improve its availability. In the context of using our website, data, including your IP address and user activities in particular, is sent to Facebook Connect / Login servers and is processed and stored outside of the European Union, e.g. in the US. The legal basis for data processing is Art. 6, Para. 1, lit. a of the GDPR. Facebook Connect / Login has certified itself in the context of the EU/US Privacy Shield Agreement (cf. https://www.privacyshield.gov/list). The data is deleted as soon as the purpose of its collection has been fulfilled. You will find further information about how the transferred data is handled in the Facebook Connect / Login privacy policy: https://www.facebook.com/privacy/explanation. You can prevent personal data (particularly your IP address) from being collected and disclosed and processing of this data by deactivating the execution of script codes in your browser, by installing a script blocker in your browser (which you will find at www.noscript.net or www.ghostery.com, for example) or by enabling your browser’s “Do Not Track” setting.

  • Facebook Custom Audience

We use a web tracking service provided by Facebook, Inc., 1601 Willow Road, Menlo Park, CA 94024, USA (hereinafter referred to as “Facebook Custom Audience”) on our website. In the context of web tracking, Facebook Custom Audience uses cookies, which are stored on your computer and enable analysis of the use of our website and your surfing behaviour (so-called tracking). We carry out this analysis based on the Facebook Custom Audience tracking service in order to continuously optimise our website and improve its availability. In the context of using our website, data, including your IP address and user activities in particular, is sent to Facebook Custom Audience servers and is processed and stored outside of the European Union, e.g. in the US. The legal basis for data processing is Art. 6, Para. 1, lit. a of the GDPR. Facebook Custom Audience has certified itself in the context of the EU/US Privacy Shield Agreement (cf. https://www.privacyshield.gov/list). The data is deleted as soon as the purpose of its collection has been fulfilled. You will find further information about how the transferred data is handled in the Facebook Custom Audience privacy policy: https://www.facebook.com/privacy/explanation. You can prevent personal data (particularly your IP address) from being collected and disclosed and processing of this data by deactivating the execution of script codes in your browser, by installing a script blocker in your browser (which you will find at www.noscript.net or www.ghostery.com, for example) or by enabling your browser’s “Do Not Track” setting.

  • Facebook Exchange (FBX)

We use a web tracking service provided by Facebook, Inc., 1601 Willow Road, Menlo Park, CA 94024, USA (hereinafter referred to as “Facebook Exchange (FBX)” on our website. In the context of web tracking, Facebook Exchange (FBX) uses cookies, which are stored on your computer and enable analysis of the use of our website and your surfing behaviour (so-called tracking). We carry out this analysis based on the Facebook Exchange (FBX) tracking service in order to continuously optimise our website and improve its availability. In the context of using our website, data, including your IP address and user activities in particular, is sent to Facebook Exchange (FBX) servers and is processed and stored outside of the European Union, e.g. in the US. The legal basis for data processing is Art. 6, Para. 1, lit. a of the GDPR. Facebook Exchange (FBX) has certified itself in the context of the EU/US Privacy Shield Agreement (cf. https://www.privacyshield.gov/list). The data is deleted as soon as the purpose of its collection has been fulfilled. You will find further information about how the transferred data is handled in the Facebook Exchange (FBX) privacy policy: https://www.facebook.com/privacy/explanation. You can prevent personal data (particularly your IP address) from being collected and disclosed and processing of this data by deactivating the execution of script codes in your browser, by installing a script blocker in your browser (which you will find at www.noscript.net or www.ghostery.com, for example) or by enabling your browser’s “Do Not Track” setting.

6. Integration of external web services and data processing outside the EU

We use active JavaScript contents from external providers (“web services”) on our website. When you access our website, these external providers may receive personal information about your visit to our website. Data may be processed outside the EU in this regard. You can prevent this from happening by installing a JavaScript blocker, such as the ‘NoScript’ browser plugin (www.noscript.net), or by disabling JavaScript in your browser. This can lead to functional restrictions on websites you visit.
We use the following external web services:

  • Google

A web service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter referred to as “Google”) is downloaded on our website. We use this data to guarantee the full functionality of our website. Your browser may transfer personal data to Google in this regard. The legal basis for data processing is Art. 6, Para. 1, lit. f of the GDPR. The legitimate interest is to ensure error-free operation of the website. Google has certified itself in the context of the EU/US Privacy Shield Agreement (cf. https://www.privacyshield.gov/list). The data is deleted as soon as the purpose of its collection has been fulfilled. You will find further information about how the transferred data is handled in Google’s privacy policy: https://www.google.com/intl/de/policies/privacy/. You can prevent Google from collecting and processing your data by deactivating the execution of script codes in your browser or by installing a script blocker in your browser (which you will find at www.noscript.net or www.ghostery.com, for example).

  • Google Video

A web service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter referred to as “Google Video”) is downloaded on our website. We use this data to guarantee the full functionality of our website. Your browser may transfer personal data to Google Video in this regard. The legal basis for data processing is Art. 6, Para. 1, lit. f of the GDPR. The legitimate interest is to ensure error-free operation of the website. Google Video has certified itself in the context of the EU/US Privacy Shield Agreement (cf. https://www.privacyshield.gov/list). The data is deleted as soon as the purpose of its collection has been fulfilled. You will find further information about how the transferred data is handled in the Google Video privacy policy: https://www.google.com/intl/de/policies/privacy/. You can prevent Google Video from collecting and processing your data by deactivating the execution of script codes in your browser or by installing a script blocker in your browser (which you will find at www.noscript.net or www.ghostery.com, for example).

  • Google APIs

A web service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter referred to as “Google APIs”) is downloaded on our website. We use this data to guarantee the full functionality of our website. Your browser may transfer personal data to Google APIs in this regard. The legal basis for data processing is Art. 6, Para. 1, lit. f of the GDPR. The legitimate interest is to ensure error-free operation of the website. Google APIs has certified itself in the context of the EU/US Privacy Shield Agreement (cf. https://www.privacyshield.gov/list). The data is deleted as soon as the purpose of its collection has been fulfilled. You will find further information about how the transferred data is handled in the Google APIs privacy policy: https://www.google.com/intl/de/policies/privacy/. You can prevent Google APIs from collecting and processing your data by deactivating the execution of script codes in your browser or by installing a script blocker in your browser (which you will find at www.noscript.net or www.ghostery.com, for example).

  • Googletagmanager.com

A web service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter referred to as “Googletagmanager.com”) is downloaded on our website. We use this data to guarantee the full functionality of our website. Your browser may transfer personal data to Googletagmanager.com in this regard. The legal basis for data processing is Art. 6, Para. 1, lit. f of the GDPR. The legitimate interest is to ensure error-free operation of the website. Googletagmanager.com has certified itself in the context of the EU/US Privacy Shield Agreement (cf. https://www.privacyshield.gov/list). The data is deleted as soon as the purpose of its collection has been fulfilled. You will find further information about how the transferred data is handled in the Googletagmanager.com privacy policy: https://www.google.com/intl/de/policies/privacy/. You can prevent Googletagmanager.com from collecting and processing your data by deactivating the execution of script codes in your browser or by installing a script blocker in your browser (which you will find at www.noscript.net or www.ghostery.com, for example).

  • Yahoo Ad Exchange (Right Media)

A web service provided by Oath (EMEA), Ltd., 5-7 Point Square, North Wall Quay, Dublin 1 (hereinafter referred to as “Yahoo Ad Exchange (Right Media)”) is downloaded on our website. We use this data to guarantee the full functionality of our website. Your browser may transfer personal data to Yahoo Ad Exchange (Right Media) in this regard. The legal basis for data processing is Art. 6, Para. 1, lit. f of the GDPR. The legitimate interest is to ensure error-free operation of the website. The data is deleted as soon as the purpose of its collection has been fulfilled.  You will find further information about how the transferred data is handled in the Yahoo Ad Exchange (Right Media) privacy policy: https://policies.yahoo.com/ie/de/yahoo/privacy/index.htm. You can prevent Yahoo Ad Exchange (Right Media) from collecting and processing your data by deactivating the execution of script codes in your browser or by installing a script blocker in your browser (which you will find at www.noscript.net or www.ghostery.com, for example).

  • YouTube

A web service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter referred to as “YouTube”) is downloaded on our website. We use this data to guarantee the full functionality of our website. Your browser may transfer personal data to YouTube in this regard. The legal basis for data processing is Art. 6, Para. 1, lit. f of the GDPR. The legitimate interest is to ensure error-free operation of the website. YouTube has certified itself in the context of the EU/US Privacy Shield Agreement (cf. https://www.privacyshield.gov/list). The data is deleted as soon as the purpose of its collection has been fulfilled. You will find further information about how the transferred data is handled in YouTube’s privacy policy: https://www.google.de/intl/de/policies/privacy/. You can prevent YouTube from collecting and processing your data by deactivating the execution of script codes in your browser or by installing a script blocker in your browser (which you will find at www.noscript.net or www.ghostery.com, for example).

  • Social plugin – “Twitter”
    • Extent of personal data processing

We have integrated a social plugin provided by the social network “Twitter”, which is operated by Twitter, Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA (hereinafter referred to as “Twitter”), on our website. If you access a page featuring such a plugin, your browser automatically establishes a background connection to Twitter’s servers. The content of the plugin is transferred directly to your browser by Twitter and is only integrated in our page. Through this integration, Twitter receives the information that your browser has loaded a specific page on our website. This also applies if you do not have a Twitter profile or are not logged into Twitter at present. This information (including your IP address) is transmitted by your browser directly to a Twitter server in the US and stored there. If you are logged into Twitter, Twitter can directly assign your visit to our website to your Twitter profile. If you interact with the plugins – for example, click the “Like” button or post a comment – this information is also transferred directly to a Twitter server and stored there. The information is also published on your Twitter profile and made accessible to your Twitter contacts who you have enabled for this.

    • Legal basis for personal data processing

Art. 6, Para. 1, lit. a of the GDPR (if you are registered with “Twitter”) and Art. 6, Para. 1. lit. f of the GDPR (if you are not registered with Twitter). Insofar as processing is carried out based on Art. 6, Para. 1, Clause 1, lit. f of the GDPR, the site operator’s legitimate interest lies in enabling user interaction with the site operator’s contents on Twitter. .

    • Purpose of data processing

The primary purpose of data collection is to offer you an opportunity for social interaction networked with Twitter and to design our website in an interactive way. Please refer to Twitter’s privacy policy (https://twitter.com/de/privacy) to find out about the extent of data collection and Twitter’s further processing and use of the data you provided, as well as your rights in this regard and the settings available to protect your privacy.

    • Duration of storage

Twitter will store the data which is relevant to the provision of the web service for as long as is necessary. If the data is subject to the legal retention requirements, deletion shall take place once the retention requirement has expired.

    • Opportunity to object and remove

If you do not want Twitter’s social plugin to be executed, you can block such execution by installing a so-called script blocker such as “NoScript”, for example. If you do not want Twitter to assign the data collected via our website to your Twitter profile, you must log out of Twitter before visiting our website. You can also prevent loading of the Twitter plugin in a targeted manner by using add-ons for your browser. For Mozilla Firefox: https://addons.mozilla.org/de/firefox/addon/Twitter-blocker/. For Opera: https://addons.opera.com/de/extensions/details/Twitter-blocker/?display=en. For Chrome: https://chrome.google.com/webstore/detail/Twitter-blocker/pjaajgndmkdhodnaeeflmchheijfjnhf. The opportunities to object and remove are additionally based on the general regulations on the right of objection and claim for deletion under data protection legislation which are outlined below in this privacy policy.

  • Social plugin – “Pinterest”
    • Extent of personal data processing

We have integrated a social plugin provided by the social network “Pinterest”, which is operated by Pinterest Inc., 808 Brannan St., San Francisco, CA 94103, USA (hereinafter referred to as “Pinterest”), on our website. If you access a page featuring such a plugin, your browser automatically establishes a background connection to Pinterest’s servers. The content of the plugin is transferred directly to your browser by Pinterest and is only integrated in our page. Through this integration, Pinterest receives the information that your browser has loaded a specific page on our website. This also applies if you do not have a Pinterest profile or are not logged into Pinterest at present. This information (including your IP address) is transmitted by your browser directly to a Pinterest server in the US and stored there. If you are logged into Pinterest, Pinterest can directly assign your visit to our website to your Pinterest profile. If you interact with the plugins – for example, click the “Like” button or post a comment – this information is also transferred directly to a Pinterest server and stored there. The information is also published on your Pinterest profile and made accessible to your Pinterest contacts who you have enabled for this.

    • Legal basis for personal data processing

Art. 6, Para. 1, lit. a of the GDPR (if you are registered with “Pinterest”) and Art. 6, Para. 1. lit. f of the GDPR (if you are not registered with Pinterest). Insofar as processing is carried out based on Art. 6, Para. 1, Clause 1, lit. f of the GDPR, the site operator’s legitimate interest lies in enabling user interaction with the site operator’s contents on Pinterest. .

    • Purpose of data processing

The primary purpose of data collection is to offer you an opportunity for social interaction networked with Pinterest and to design our website in an interactive way. Please refer to Pinterest’s privacy policy (https://policy.pinterest.com/de/privacy-policy) to find out about the extent of data collection and Pinterest’s further processing and use of the data you provided, as well as your rights in this regard and the settings available to protect your privacy.

    • Duration of storage

Pinterest will store the data which is relevant to the provision of the web service for as long as is necessary. If the data is subject to the legal retention requirements, deletion shall take place once the retention requirement has expired.

    • Opportunity to object and remove

If you do not want Pinterest’s social plugin to be executed, you can block such execution by installing a so-called script blocker such as “NoScript”, for example. If you do not want Pinterest to assign the data collected via our website to your Pinterest profile, you must log out of Pinterest before visiting our website. You can also prevent loading of the Pinterest plugin in a targeted manner by using add-ons for your browser. For Mozilla Firefox: https://addons.mozilla.org/de/firefox/addon/Pinterest-blocker/. For Opera:https://addons.opera.com/de/extensions/details/Pinterest-blocker/?display=en. For Chrome: https://chrome.google.com/webstore/detail/Pinterest-blocker/pjaajgndmkdhodnaeeflmchheijfjnhf. The opportunities to object and remove are additionally based on the general regulations on the right of objection and claim for deletion under data protection legislation which are outlined below in this privacy policy.

  • Social plugin – “Google+”
    • Extent of personal data processing

We have integrated a social plugin provided by the social network “Google+”, which is operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, CA, USA (hereinafter referred to as “Google+”), on our website. If you access a page featuring such a plugin, your browser automatically establishes a background connection to Google+’s servers. The content of the plugin is transferred directly to your browser by Google+ and is only integrated in our page. Through this integration, Google+ receives the information that your browser has loaded a specific page on our website. This also applies if you do not have a Google+ profile or are not logged into Google+ at present. This information (including your IP address) is transmitted by your browser directly to a Google+ server in the US and stored there. If you are logged into Google+, Google+ can directly assign your visit to our website to your Google+ profile. If you interact with the plugins – for example, click the “Like” button or post a comment – this information is also transferred directly to a Google+ server and stored there. The information is also published on your Google+ profile and made accessible to your Google+ contacts who you have enabled for this.

    • Legal basis for personal data processing

Art. 6, Para. 1, lit. a of the GDPR (if you are registered with “Google+”) and Art. 6, Para. 1. lit. f of the GDPR (if you are not registered Google+). Insofar as processing is carried out based on Art. 6, Para. 1, Clause 1, lit. f of the GDPR, the site operator’s legitimate interest lies in enabling user interaction with the site operator’s contents on Google+. .

    • Purpose of data processing

The primary purpose of data collection is to offer you an opportunity for social interaction networked with Google+ and to design our website in an interactive way. Please refer to Google+’s privacy policy (google.com/privacy) to find out about the extent of data collection and Google+’s further processing and use of the data you provided, as well as your rights in this regard and the settings available to protect your privacy.

    • Duration of storage

Google+ will store the data which is relevant to the provision of the web service for as long as is necessary. If the data is subject to the legal retention requirements, deletion shall take place once the retention requirement has expired.

    • Opportunity to object and remove

If you do not want Google+’s social plugin to be executed, you can block such execution by installing a so-called script blocker such as “NoScript”, for example. If you do not want Google+ to assign the data collected via our website to your Google+ profile, you must log out of Google+ before visiting our website. You can also prevent loading of the Google+ plugin in a targeted manner by using add-ons for your browser. For Mozilla Firefox: https://addons.mozilla.org/de/firefox/addon/Google +-blocker/. For Opera: https://addons.opera.com/de/extensions/details/Google+-blocker/?display=en. For Chrome: https://chrome.google.com/webstore/detail/Google +-blocker/pjaajgndmkdhodnaeeflmchheijfjnhf. The opportunities to object and remove are additionally based on the general regulations on the right of objection and claim for deletion under data protection legislation which are outlined below in this privacy policy.

7. Information about the use of cookies

  • Extent of personal data processing

We use cookies on various pages to enable the use of certain functions on our website. The so-called ‘cookies’ are small text files which your browser can save on your computer. These text files contain a characteristic character string which enables unique identification of the browser the next time our website is called up. The process of saving a cookie file is also known as ‘setting a cookie’.

  • Legal basis for personal data processing

Art. 6, Para. 1, lit. f of the GDPR. (legitimate interest). Our legitimate interest is to maintain the full functionality of our website, to increase usability and to enable more individual customer contact. We can only identify individual site visitors using the cookie technology if said site visitors sent us corresponding personal data based on separate consent beforehand.

  • Purpose of data processing

The cookies are set by our website to maintain the full functionality of our website and to improve usability. The cookie technology also enables us to recognise individual visitors using pseudonyms, e.g. an individual, arbitrary ID, so we can offer more individual services.

  • Duration of storage

Our cookies are stored until they are deleted from your browser or, if the cookie is a session cookie, until the session is ended.

  • Opportunity to object and remove

According to your requirements, you can make settings in your browser so that you generally prevent cookies from being set, are only informed of them, can decide on whether to accept cookies on a case-by-case basis or categorically accept the setting of cookies. Cookies can be used for different purposes, e.g. to identify that your PC has previously connected to our website (permanent cookies) or to save your most recently viewed websites (session cookies). We use cookies to offer you increased user comfort. We advise that you accept cookies for our website to use our convenience functions. The opportunities to object and remove are additionally based on the general regulations on the right of objection and claim for deletion under data protection legislation which are outlined below in this privacy policy.

8. Data security and data protection, communication by email

When it is collected, stored and processed, your personal data is protected by means of technical and organisational measures to ensure that it is inaccessible to third parties. Since we cannot guarantee complete data security on the transmission path to our IT systems during unencrypted communication by email, we advise sending highly confidential information using encrypted communication or by post.

9. Revocation of consent – data information and change requests – deleting and blocking data

According to the German Federal Data Protection Act, you have a right to obtain free information concerning the data stored about you and, if necessary, a right to correct, block or delete such data. Your data is then deleted unless statutory regulations to the contrary exist. You can revoke the permission you granted us to use your personal data at any time. You are more than welcome to send any information, deletion and correction requests concerning your data, as well as any suggestions, to the following address at any time:

Gym Aesthetics Sportsleish Limited
Flat F, 35/F, Montery Plaza
15 Chong Yip Street, Kwun Tong, Hong Kong

Email: service.hk@gymaesthetics.com
Tel.: +852 36203450

10. Right to lodge a complaint with the supervisory authority according to Art. 77 I of the GDPR

If you suspect that your data is being processed unlawfully on our site, you can naturally obtain judicial clarification of the issue at any time. Regardless of this, you have the option of contacting a supervisory authority. You have a right to lodge a complaint in the EU member state of your place of residence, your workplace and/or the place of the suspected violation, i.e. you can choose the supervisory authority you wish to contact from the aforementioned locations. The supervisory authority with whom the complaint was lodged then informs you of the status and results of your petition, including the possibility of a judicial legal remedy according to Art. 78 of the GDPR.

Created by:
© IT law firm DURY – www.dury.de
© Website-Check GmbH – www.website-check.de