Privacy Policy
1. Controller
Studio Sun & Sea
Owner: Miloš Borojević
Registered Office (Germany):
Pfarrtannen 7
49808 Lingen, Deutschland
Secondary Location (USA):
9215 Jasmine Lane
Irving, TX 75063, USA
E-Mail: privacy@studiosunandsea.com
2. General Information
We process personal data of our users only to the extent necessary to provide a functional website, our contents, and our services. Personal data is processed regularly only with the user's consent, for the performance of a contract, or when authorized by statutory provisions.
3. Hosting and Log Files
a) Description and scope of data processing
When accessing our website, our hosting provider (Cloudflare) automatically collects and stores data and information from the computer system of the calling device. This includes:
- IP address and technical network metadata
- Date and time of access
- Browser type and version used
- Operating system of the end device
- Referrer URL (the previously visited page)
- Pages accessed and click paths on our website
These data are stored in server log files. They are not merged with other data sources.
b) Legal basis
The legal basis for temporary storage of data and log files is Art. 6(1)(f) GDPR (legitimate interest).
c) Purpose of processing
Temporary storage of the IP address is necessary to deliver the website to your device. Storage in log files ensures functionality, security, stability, and optimization of our information technology systems.
d) Recipient and International Data Transfers
The service provider is Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Data processing may take place on US servers. Data transfers are legally secured via a Data Processing Addendum (DPA) based on EU Standard Contractual Clauses.
4. Cookies
Our website does not use tracking or marketing cookies. We exclusively use cookies that are technically strictly required for the operation and functionality of embedded services (such as the Mindbody booking widget).
5. Contact by Email or Form
a) Description and scope
When contacting us via email or a contact form, the personal data you provide (e.g., name, email address, message content) is stored and processed to handle your request and resolve subsequent follow-up queries.
b) Legal basis
The legal basis is Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in processing user inquiries efficiently).
c) Purpose
The data processing serves solely to handle your specific request and to ensure communication with you.
d) Storage duration
Data are deleted as soon as they are no longer required to achieve the purpose of their collection, provided no statutory commercial or tax retention obligations apply.
6. Mindbody Integration (Schedule & Booking)
a) Description and Scope of Data Processing
Our website integrates third-party features and services provided by Mindbody Limited (6th Floor, 50 Farringdon Road, London, EC1M 3HE, United Kingdom), a subsidiary of Mindbody, Inc. (USA). This integration facilitates class scheduling, client profile registration, user bookings, and secure payment processing. When you access these features, your browser establishes a direct connection to Mindbody’s servers. Data processed may include IP addresses, browser and device configuration details, usage data (clicks, timestamps), and profile or billing information necessary to execute your bookings.
b) Legal Basis for Processing
For users within the European Economic Area (EEA) and the United Kingdom, processing of account, booking, and transaction data is based on Art. 6(1)(b) GDPR / UK GDPR. Processing of technical metadata is based on our legitimate interest in providing an optimized scheduling infrastructure pursuant to Art. 6(1)(f) GDPR / UK GDPR. For United States residents, data processing is based on your voluntary consent granted at account creation.
c) International Data Transfers and Safeguards
The technical data recipient is the infrastructure parent provider: Mindbody, Inc., 4051 Broad Street, Suite 179, San Luis Obispo, CA 93401, USA. To guarantee an adequate level of data protection for European and UK users, Mindbody, Inc. complies with the EU-U.S. Data Privacy Framework (DPF) and the UK Extension to the DPF. Data streams are further protected under Standard Contractual Clauses (SCCs).
d) Purpose and Retention
Data is processed exclusively to manage your class reservations, process secure transactions, and ensure scheduling administrative tracking across our locations. Data will be retained by Mindbody for as long as your account remains active or as required by statutory retention laws. For further information, see the official Mindbody Privacy Policy.
7. Hosting via Cloudflare Pages
Our website is hosted on Cloudflare Pages. The provider processes technical connection data (see section 3) to provide, secure, and optimize the website network traffic. For more information, please see the Cloudflare Privacy Policy.
8. External Links
Our website contains links to external third-party websites. We have no control over their contents or data management frameworks. The respective privacy policies of those external operators apply exclusively.
9. Exali Liability Seal
a) Description and scope
Our website includes a graphical integration of the liability seal provided by Exali AG. The seal element is loaded directly from Exali’s servers, which requires processing technical connection parameters (including your IP address, browser type, and timestamp) to deliver the image block. Clicking the seal redirects you to Exali's validation servers to verify active coverage.
For details, see the Exali Privacy Policy.
b) Legal basis
The legal basis for this temporary data processing is Art. 6(1)(f) GDPR (legitimate interest).
c) Purpose
Providing legally required verifications regarding our professional liability insurance status according to § 2(1) No. 11 DL-InfoV in a transparent and structured manner.
d) Legitimate interest
Offering an appealing online presence and fulfilling mandatory legal transparency guidelines while strengthening consumer trust through verified insurance coverage.
10. Rights of Data Subjects
You have the following statutory rights under the GDPR:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure / right to be forgotten (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent at any time (Art. 7(3) GDPR)
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
The competent supervisory authority for our registered office is: Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Germany. For participants residing in the US (especially Texas), local statutory consumer privacy provisions regarding data access and deletion options under applicable US state regulations are fully honored.
11. Right to Object (Art. 21 GDPR)
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(f) GDPR (legitimate interest). We will cease processing the personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims.
12. Changes to This Privacy Policy
We reserve the right to update this Privacy Policy to reflect changing legal guidelines, structural adjustments in processing setups across our transatlantic locations, or technical changes (such as system or application updates). The version accessible at the time of your visit applies.