Privacy Policy
PEAK FIT
Privacy Policy
Effective date: 23 August 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other applicable data protection laws for the processing of personal data in connection with Peak Fit is:
Edizon Gym GmbH
Waldeckstrafle 49
79400 Kandern
Germany
Email: info@peak-fit.de
Telephone: +49 7626 5519949
2. Personal Data We Process
In connection with a membership or the use of our services, we may in particular
process the following personal data:
• first and last name;
• date of birth;
• address;
• email address;
• telephone and mobile number;
• payment information, in particular IBAN and other information required for SEPA
payments as well as, where applicable, credit or debit card details;
• membership, customer and contract data;
• information about membership fees, payments, outstanding amounts and
payment status;
• access and check-in data;
• booking data, in particular for classes, appointments and personal training;
• communication data and the content of communications with Peak Fit;
• technical data where our website, member Wi-Fi or other digital services are
used.
Health or medical data is generally not collected as part of an ordinary membership.
A photograph or copy of an identity document is generally not required for ordinary
membership registration.
If, in individual cases, special categories of personal data within the meaning of Article 9 GDPR are processed, this will only take place where there is an appropriate legal basis or where explicit consent has been provided.
3. Membership and Contract Administration
We process personal data for the establishment, performance and administration of
memberships and for the provision of our contractual services.
This includes in particular:
• processing membership applications;
• entering into and administering membership agreements;
• managing member accounts;
• granting and managing access to the gym;
• managing bookings and appointments;
• carrying out and administering personal-training bookings;
• billing and collection of membership fees;
• handling outstanding amounts;
• membership-related communications;
• customer service and handling enquiries.
Processing is generally carried out on the basis of Article 6(1)(b) GDPR where it is
necessary for entering into or performing the membership agreement.
Where we process data in order to comply with statutory retention, documentation, tax or commercial-law obligations, the processing is carried out on the basis of Article 6(1)(c) GDPR.
Where processing is necessary for the purposes of our legitimate interests or those of a third party and such interests are not overridden by the interests or fundamental rights of the data subject, processing is carried out on the basis of Article 6(1)(f) GDPR.
Our legitimate interests include, in particular, the proper organisation of gym operations, the enforcement of contractual claims, the prevention of misuse and the protection of our property and facilities.
4. Magicline and MySports
We use Magicline and the MySports app to administer memberships and related
services.
The following data in particular may be processed through these systems:
• master data and contact details;
• membership and contract data;
• booking data;
• payment information;
• access and check-in data;
• information about membership status;
• technical data required for the use of the respective digital functions.
Processing is carried out in particular for membership administration, the provision of
digital member functions, booking management and access control.
The legal basis is generally Article 6(1)(b) GDPR.
Where the respective providers process personal data on our behalf, this is carried out on the basis of a data processing agreement in accordance with Article 28 GDPR, where such an agreement is legally required.
5. Payment Processing, FINION Capital and MemberCash
For payment processing and, where applicable, the handling and collection of
outstanding amounts, we use services including FINION Capital / MemberCash.
In this context, the following information in particular may be processed or transferred:
• name and contact details;
• contract and membership data;
• payment data;
• details of outstanding amounts;
• payment status;
• information required for the relevant payment or debt-collection process.
The processing of regular membership fees is generally carried out on the basis of
Article 6(1)(b) GDPR.
Where personal data is processed for the establishment, enforcement or defence of
claims, the processing may additionally be based on Article 6(1)(f) GDPR. Our legitimate interest in this case is, in particular, the enforcement of legitimate contractual payment claims.
Where statutory documentation and retention obligations apply, processing is
additionally carried out on the basis of Article 6(1)(c) GDPR.
6. Access and Check-in Data
Access to Peak Fit may be provided by means of a QR code or a designated wristband.
When entering the gym, the following data in particular may be stored:
• identity or member account;
• date and time of access;
• where applicable, the access medium used;
• information relating to access authorisation.
We process this data in particular for:
• granting and controlling contractually agreed access;
• membership administration;
• preventing unauthorised use;
• ensuring proper gym operations;
• investigating technical or organisational access issues;
• maintaining security within the gym.
Where processing is necessary for the performance of the membership agreement, it is carried out on the basis of Article 6(1)(b) GDPR.
Where the data is used to prevent misuse, protect our facilities or investigate specific
incidents, processing may be based on Article 6(1)(f) GDPR.
7. Video Surveillance
Video surveillance is used in certain areas of Peak Fit.
Video surveillance serves in particular the following purposes:
• protection of members, employees and other persons present;
• exercising our rights as premises owner/operator;
• protection of our property and facilities;
• prevention and, where necessary, investigation of theft, property damage and
other security-related incidents;
• prevention of unauthorised use of the gym.
Video surveillance is only carried out in designated areas. Changing rooms, showers
and sanitary areas are not subject to video surveillance.
Processing is carried out on the basis of Article 6(1)(f) GDPR in conjunction with the
applicable statutory provisions governing video surveillance, in particular Section 4 of
the German Federal Data Protection Act (BDSG), where applicable.
Our legitimate interest lies in particular in the protection of persons and property,
exercising our rights as premises owner/operator and preventing and investigating
specific security-related incidents.
Video surveillance is indicated in the relevant areas by appropriate notices.
Retention period for video recordings: 30 days.
Recordings are generally deleted after this period unless they are required for longer due to a specific incident, for further investigation, the establishment, exercise or defence of legal claims, or disclosure to the competent authorities.
Access to recordings is restricted to authorised persons and, where applicable,
authorities or other recipients where there is an appropriate legal basis.
8. Communication with Members
We use members’ contact details to administer their membership and to communicate about matters relating to the membership agreement.
Communication may in particular take place via:
• email;
• telephone;
• SMS or comparable communication services;
• WhatsApp, where this communication channel is used.
Contract-related communications may include information relating to membership,
fees, bookings, appointments, opening hours, contract changes or other organisational information required for the provision of our services.
Where communication is required for the performance of the membership agreement, processing is carried out on the basis of Article 6(1)(b) GDPR.
9. Advertising and Direct Marketing
We distinguish promotional communications from communications required for the
performance of the membership agreement.Advertising by email, telephone, WhatsApp or comparable electronic communication channels is only carried out where the relevant legal requirements are met.
Where consent is required, processing is carried out on the basis of Article 6(1)(a)
GDPR.
Consent may be withdrawn at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before its
withdrawal.
Where the statutory requirements for direct marketing to existing customers without
separate consent are met, such marketing may be carried out to the extent permitted by law.
You may object at any time to the processing of your personal data for direct-marketing purposes.
To do so, simply contact:
Following an objection, your personal data will no longer be used for the relevant direct-marketing purposes.
10. WhatsApp
Where Peak Fit offers communication via WhatsApp and you use this communication
channel, your telephone number, name, communication content and technical
connection and metadata may in particular be processed.
Peak Fit uses WhatsApp Business for this purpose.
Communication via WhatsApp generally takes place only where this communication
channel is used or requested by the member.
Where communication is required for the performance of the membership agreement or a service requested by you, the legal basis is Article 6(1)(b) GDPR.
Where WhatsApp is used for promotional communications, this is only done in
compliance with the applicable statutory requirements and any required consent.
When WhatsApp is used, personal data may also be processed by the service provider.
This may involve transfers of personal data to countries outside the European Economic Area.
11. Social Media
Peak Fit maintains profiles on the following social networks:
• Instagram;
• Facebook.
If you visit or interact with our social-media pages, personal data may be processed
both by Peak Fit and by the respective platform operator.
This may in particular include:
• profile and account information;
• comments and messages;
• reactions and interactions;
• usage and reach data;
• technical data and online identifiers.
We use our social-media presence in particular for public relations, information about
our services, communication with members and interested persons, and promotional
purposes.
Where processing is based on our legitimate interests, the legal basis is Article 6(1)(f)
GDPR. Our legitimate interest lies in particular in modern public relations and
communication with members and interested persons.
Where consent is required, processing is carried out on the basis of Article 6(1)(a)
GDPR.
For certain processing activities within social networks, the relevant platform operator
may act independently or jointly with us as a controller. Further information can be
found in the privacy information of the respective platform operator.
12. Photographs and Videos for Public Relations and Advertising
Photographs or videos in which individuals are identifiable and which are intended to be used for advertising, social media, our website or other publications will only be
processed and published where there is an appropriate legal basis.
Where consent is required, it will be obtained separately.
In such cases, the legal basis is generally Article 6(1)(a) GDPR.
Consent may be withdrawn at any time with effect for the future.
13. Website, Cookies and Similar Technologies
When you visit our website, technically necessary information may be processed. This
may in particular include:
• IP address;
• date and time of access;
• pages or files accessed;
• browser type and browser version;
• operating system;
• referrer URL;
• technical device and connection information.
Where this processing is necessary to provide our website technically, ensure system
security or identify errors, it is carried out on the basis of Article 6(1)(f) GDPR.
Our legitimate interest lies in the secure, stable and functional provision of our website.
Where information is stored on or read from your terminal device, the statutory
requirements of Section 25 TDDDG also apply.
Cookies and comparable technologies that are not technically necessary, in particular
for analytics, marketing or advertising purposes, are generally only used after the
required consent has been obtained.
Consent may be changed or withdrawn at any time with effect for the future through the consent-management system used on our website.
14. Google Analytics and Other Analytics Services
Peak Fit uses Google Analytics to analyse and improve its online services.
The following data in particular may be processed:
• IP-related information;
• online identifiers;
• device and browser information;
• information about page views and usage behaviour;
• technical information;
• information about how users reached and interacted with our website.
Where technically non-essential information is stored on or read from your terminal
device, this only takes place after prior consent in accordance with Section 25(1)
TDDDG.
Where personal data is processed, the legal basis is Article 6(1)(a) GDPR.
Consent may be withdrawn at any time through our consent-management system.
15. Google Ads, Meta Ads and Online Advertising
Peak Fit uses Google Ads, Meta Ads, Meta Pixel as well as advertising and marketing functions provided by Instagram and Facebook in order to measure the reach of our services, display advertising and evaluate the success of advertising campaigns.
The following data in particular may be processed:
• online identifiers;
• cookie or device identifiers;
• IP-related information;
• browser and device information;
• information about interactions with our website or advertisements;
• information used to measure reach and advertising performance.
Where information is stored on or read from your terminal device and this processing is not technically necessary, this only takes place after prior consent in accordance with Section 25(1) TDDDG.
Personal data is generally processed on the basis of Article 6(1)(a) GDPR.
Consent may be withdrawn or changed at any time with effect for the future through our consent-management system.
16. Online Bookings and Personal Training
We offer the option of booking services, appointments and personal training online or through the membership systems we use.
For this purpose, we process the data required to create, administer and carry out the relevant booking.
This may in particular include:
• name;
• membership number or member account;
• contact details;
• appointment and booking information;
• information relating to the booked service.
The legal basis is generally Article 6(1)(b) GDPR.
Health or medical information is generally not requested as part of ordinary bookings.
If health information is required for certain services in individual cases, it will only be
processed where an appropriate legal basis exists.
17. Member Wi-Fi
Peak Fit provides members with Wi-Fi access via PYUR.
Depending on the technical configuration, the following technical data in particular may be processed when the Wi-Fi is used:
• IP address;
• MAC address or other device identifiers;
• time and duration of a connection;
• technical connection information;
• where applicable, authentication data.
Processing is carried out in particular for the provision and security of the Wi-Fi service and to ensure network and IT security.
Where the provision of Wi-Fi forms part of our contractual services, processing may be based on Article 6(1)(b) GDPR.
Where processing is necessary to ensure IT and network security, it is carried out on the basis of Article 6(1)(f) GDPR.
Our legitimate interest lies in particular in the secure and uninterrupted provision of our network.
18. Recipients and Categories of Recipients
Personal data is only transferred to external parties where this is necessary for the
relevant purposes, where there is a legal obligation to do so, or where another legal
basis for the transfer exists.
Recipients or categories of recipients may in particular include:
• providers of gym and membership-management software;
• booking-system providers;
• access-control system providers;
• payment service providers and banks;
• debt-management and debt-collection service providers;
• IT and hosting service providers;
• communication service providers;
• website and consent-management system providers;
• analytics and advertising service providers;
• social-media platforms;
• Wi-Fi and network service providers;
• tax advisers, auditors or other professional advisers;
• authorities and courts where there is a legal obligation or another legal basis for
disclosure.
The providers used by us include in particular Magicline, MySports, FINION Capital / MemberCash, PYUR and the Google and Meta services used by Peak Fit.
Where a service provider processes personal data exclusively on our behalf, we enter
into a data processing agreement in accordance with Article 28 GDPR, where legally
required.
19. Transfers of Personal Data to Third Countries
Some of the providers we use may also process personal data outside the European
Union or the European Economic Area.
Personal data is only transferred to a third country where the applicable legal
requirements are met.
This may in particular take place on the basis of:
• an adequacy decision of the European Commission pursuant to Article 45
GDPR;
• appropriate safeguards pursuant to Article 46 GDPR, in particular the European
Commission’s Standard Contractual Clauses;
• or another legal basis provided for by law.
Where a provider in the United States is certified under a data-protection framework
recognised by the European Commission and that framework applies to the relevant
transfer, the transfer may take place on the basis of the corresponding adequacy
decision.
Where Standard Contractual Clauses or other appropriate safeguards are used, further information may be requested from us.
20. Retention and Deletion
We retain personal data only for as long as necessary for the relevant processing
purpose.
Once the relevant purpose no longer applies, personal data is deleted or restricted
unless statutory retention obligations or other legal reasons require longer storage.
In particular, commercial and tax-law retention obligations may require contractual,
accounting or billing records to be retained for several years after the end of the
membership.
The following criteria apply in particular to individual categories of data:
• membership and contract data: until the end of the membership and thereafter
in accordance with applicable statutory retention and limitation periods;
• accounting and payment records: in accordance with applicable tax and
commercial-law retention requirements;
• outstanding amounts and debt management: until the matter has been fully
resolved or concluded and, where applicable, thereafter in accordance with
statutory retention and limitation periods;
• video recordings: generally 30 days, unless longer retention is required due to a
specific incident;
• marketing consents and evidence: for as long as the consent is relied upon and
thereafter where necessary to document lawful processing or comply with
statutory evidence requirements;
• communication data: for as long as necessary to deal with the relevant enquiry
or administer the membership and, where applicable, in accordance with
statutory retention or limitation periods;
• website, analytics and advertising data: in accordance with the retention and
deletion periods actually configured for the relevant service.
Where data is required for the establishment, exercise or defense of legal claims, it may be retained until the relevant matter has been concluded or the applicable limitation periods have expired.
21. Requirement to Provide Personal Data
Certain personal data is required in order to enter into and perform a membership
agreement.
Without the necessary master, contact, contract and payment data, we may be unable to enter into a membership agreement or provide certain services.
Providing data for voluntary marketing activities or comparable optional processing
activities is generally voluntary.
22. Rights of Data Subjects
Subject to the applicable statutory requirements, you have the following rights in
particular:
Right of Access
Under Article 15 GDPR, you may request information as to whether and which personal data relating to you we process.
Right to Rectification
Under Article 16 GDPR, you may request the correction of inaccurate personal data or the completion of incomplete personal data.
Right to Erasure
Under the conditions set out in Article 17 GDPR, you may request the deletion of your personal data.
Right to Restriction of Processing
Under the conditions set out in Article 18 GDPR, you may request that the processing of your personal data be restricted.
Right to Data Portability
Where the statutory requirements are met, under Article 20 GDPR you may request to receive personal data that you have provided to us in a structured, commonly used and machine-readable format or to have it transferred to another controller.
Right to Object
Where personal data is processed on the basis of Article 6(1)(e) or (f) GDPR, you have the right, under the conditions set out in Article 21 GDPR, to object to the processing on grounds relating to your particular situation.
Where personal data is processed for direct-marketing purposes, you may object to
such processing at any time and without stating reasons.
Withdrawal of Consent
Consent that has been provided may be withdrawn at any time with effect for the future.
The lawfulness of processing carried out on the basis of consent prior to its withdrawal remains unaffected.
To exercise your rights, please contact:
Edizon Gym GmbH
Waldeckstrafle 49
79400 Kandern
Germany
Email: info@peak-fit.de
Telephone: +49 7626 5519949
23. Right to Lodge a Complaint with a Data Protection Supervisory Authority
Under Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes applicable data protection law.
For Peak Fit, the relevant supervisory authority is in particular:
The State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI BW)
Heilbronner Strafle 35
70191 Stuttgart
Germany
Postal address:
Postfach 10 29 32
70025 Stuttgart
Germany
Telephone: +49 711 615541-0
Email: poststelle@lfdi.bwl.de
24. Changes to this Privacy Policy
We may amend this Privacy Policy if our services, technical systems, processing
activities or legal requirements change.
The current version applies.
The current Privacy Policy will be made available to members in an appropriate manner and may in particular be accessed via our website or through the information channels provided by Peak Fit.
