PRIVACY POLICY
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Ayleen Wollenweber (AYLEAN)
Eichendorffstraße 9
31535 Neustadt am Rübenberge, Germany
Email: info@aylean.de
2. General
When you visit this website (aylean.de), certain personal data are processed for technical reasons. This privacy policy informs you about which data are collected, for what purpose, on which legal basis, and what rights you have.
Personal data are processed exclusively in accordance with the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
This website is deliberately designed to minimise data: no tracking, marketing or analytics cookies are used, and no web analytics or tracking service is employed. Beyond the page request itself, your IP address is not stored; it arises only for technical reasons in the hosting provider's server logs (see section "Hosting") and may be processed as part of error monitoring (see section "Error monitoring"). For booking requests, newsletter sign-ups and the waitlist, no browser identifier (user-agent) is stored; your IP address is processed there for abuse prevention (rate limiting) not in plain text but solely as a SHA-256 hash, and is deleted after no more than 3 hours (booking request and newsletter) or 48 hours (waitlist).
3. Hosting — Vercel
This website is hosted by:
Vercel Inc.
440 N Barranca Avenue #4133
Covina, CA 91723, USA
Each time you access this website, your browser automatically transmits technical connection data to the hosting provider. These server logs contain:
- IP address of the requesting device
- Date and time of the request
- URL accessed
- HTTP status code and amount of data transferred
- Browser type and operating system (user-agent)
These data are technically necessary to deliver the website and are deleted automatically after a short period. They are not merged with other data sources.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure and uninterrupted operation of the website).
Vercel processes data in the USA and is certified under the EU-US Data Privacy Framework (DPF). A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with Vercel.
Further information: Vercel Privacy Policy · Vercel DPA
4. Database — Supabase
The data collected via the booking form, the newsletter sign-up and the waitlist are stored in databases operated by the following provider:
Supabase Pte. Ltd
65 Chulia Street #38-02/03, OCBC Centre
Singapore 049513, Singapore
The databases are operated exclusively in a data centre within the European Union (Frankfurt region); your data are therefore stored within the EU. Access to the stored data is technically restricted to the operation of this website and secured against unauthorised access; the data are not publicly accessible.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure and reliable storage of booking, newsletter and waitlist data). The underlying processing in each case is governed by the sections "Booking request", "Newsletter" and "Waitlist".
Supabase Pte. Ltd is based in Singapore; insofar as data are transferred to third countries outside the EU, the transfer is safeguarded by the European Commission's Standard Contractual Clauses (SCC). A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with Supabase.
Further information: Supabase Privacy Policy · Supabase DPA
5. Email delivery — Resend
We use the following service to send emails automatically:
Resend (Plus Five Five, Inc.)
2261 Market Street #5039
San Francisco, CA 94114, USA
On our behalf, Resend sends (a) the notification email to us for each booking request, (b) the automatic acknowledgement of your booking request to you, (c) the confirmation (double opt-in) and unsubscribe emails belonging to the newsletter sign-up, and (d) the confirmation and information emails of the waitlist. The data contained in each email are processed (in particular email address, name and message content), together with technical sending and delivery information.
Legal basis: Art. 6(1)(b) GDPR for the booking emails (pre-contractual measure, see section "Booking request") and Art. 6(1)(a) GDPR for the newsletter and waitlist emails (consent, see sections "Newsletter" and "Waitlist").
Resend processes data in the USA. The data transfer is safeguarded by the EU-US Data Privacy Framework (DPF) and/or the European Commission's Standard Contractual Clauses (SCC). A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with Resend.
Further information: Resend Privacy Policy · Resend DPA
6. Error monitoring — Sentry
To ensure the stable and secure operation of this website, we use the Sentry service to capture and analyse technical errors automatically:
Functional Software, Inc. (dba Sentry)
45 Fremont Street, 8th Floor
San Francisco, CA 94105, USA
If an error occurs during your visit, technical data are transmitted to Sentry, in particular:
- Error and crash reports (stack traces)
- IP address
- Browser and device information
- The page you accessed
The data are processed and stored exclusively in a data centre within the European Union (EU region, de.sentry.io).
We have configured Sentry to protect your privacy: no user data, cookies, HTTP headers or form contents are captured, any parameters in the address bar (URL) are removed before transmission, no session recording (Session Replay) takes place, and local variable values are not captured.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the stable, secure and error-free operation of the website).
Sentry is operated by a US parent company; insofar as a data transfer to the USA takes place, it is safeguarded by the EU-US Data Privacy Framework (DPF) and/or the European Commission's Standard Contractual Clauses (SCC). A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with Sentry.
Further information: Sentry Privacy Policy · Sentry DPA
7. Booking request (booking form “/bookings”)
Using the booking form at "/bookings", you can send us a non-binding request for 1:1 coaching or a corporate event. The following data are collected:
- Type of request (1:1 coaching or corporate event)
- First name and surname
- Email address
- Preferred contact channel (email, WhatsApp or Instagram)
- Phone number (only if you choose to be contacted via WhatsApp)
- Instagram username (optional; required if you choose to be contacted via Instagram)
- For 1:1 coaching: the selected offer, preferred time of day (for training in the studio only) and your answers on training goal and training frequency
- For a corporate event: company, group size, occasion and notes, and a preferred date or date range
- The estimated price shown to you
- The time at which you confirmed the privacy notice
- Consent to the newsletter (optional, see section "Newsletter")
These data are stored in the database (see section "Database"), together with a processing status. No browser identifier (user-agent) is stored. For abuse prevention (rate limiting), your IP address is not stored in plain text; it is processed solely as a SHA-256 hash and deleted automatically after no more than 3 hours. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interest in preventing abuse). To process your request, a notification email containing the above details is also sent to us via the Resend service (see section "Email delivery"), and you receive an automatic acknowledgement at the email address you provided.
Providing the data marked as required is necessary for us to process your request. Confirming the privacy notice serves as acknowledgement; any newsletter consent is independent of this and voluntary.
Legal basis: Art. 6(1)(b) GDPR (performance of pre-contractual measures taken at the request of the data subject).
Retention period: Requests that do not lead to a contract are deleted after 12 months, unless statutory retention obligations apply.
8. Contact via WhatsApp or Instagram
In the booking form you can tell us how we should contact you about your request. If you choose WhatsApp or Instagram, we contact you via that service. In doing so, your phone number or Instagram username and the content of the communication are processed by the respective provider:
Meta Platforms Ireland Limited (Instagram) or WhatsApp Ireland Limited
Merrion Road, Dublin 4, D04 X2K5, Ireland
The provider may also transfer data to the USA; the transfer is safeguarded by the EU-US Data Privacy Framework (DPF) and/or the European Commission's Standard Contractual Clauses (SCC). We use the channel you choose solely to contact you about your request. Using these channels is voluntary; alternatively, you can choose to be contacted by email.
Legal basis: Art. 6(1)(b) GDPR (performance of pre-contractual measures taken at your request).
Further information: WhatsApp Privacy Policy · Instagram Privacy Policy
9. Newsletter (double opt-in)
In the booking form you can voluntarily tick a box to receive our newsletter with news about classes and events. The box is not pre-ticked and is separate from confirming the privacy notice; your request is processed either way. Sign-up uses the double opt-in procedure: after submitting, you receive a confirmation email, and only once you confirm the sign-up on the linked page are you on the newsletter list.
The following data are stored for the newsletter in a separate data set:
- Email address
- A hash of your email address (SHA-256), see below
- The exact wording of the consent declaration shown to you
- Time and language of the consent
- A confirmation token valid for 30 days and a non-expiring unsubscribe token
- Timestamps for confirmation, sending and unsubscribing
- A reference to the booking request with which you signed up
No browser identifier (user-agent) is stored. When you open the confirmation or unsubscribe page, your IP address is not stored in plain text but processed solely as a SHA-256 hash for abuse prevention (rate limiting) and deleted automatically after no more than 3 hours (Art. 6(1)(f) GDPR — legitimate interest in preventing abuse). The confirmation and unsubscribe emails are sent via the Resend service (see section "Email delivery").
When you unsubscribe, your email address is deleted. What is kept afterwards is the hash of your email address, the consent text, and the times of consent, confirmation and unsubscribing. The purpose is to prove that and when you consented and withdrew your consent (Art. 7(1) GDPR), and to recognise the same address if you sign up again. The hash is created without a random value ("salt"): anyone who knows your email address can compute the same hash and match it. It is therefore pseudonymous, not anonymous. The legal basis for this retention is our legitimate interest in being able to provide this proof (Art. 6(1)(f) GDPR). Signing up again starts a new double opt-in procedure.
Legal basis: Art. 6(1)(a) GDPR (consent).
Withdrawal: You can withdraw your consent at any time with effect for the future, via the unsubscribe link contained in every newsletter email. The unsubscribe link does not expire. The lawfulness of the processing carried out before the withdrawal remains unaffected.
Retention period: Unconfirmed sign-ups are deleted automatically after 30 days; confirmed sign-ups are kept until you withdraw your consent. The hash and the proof of consent are deleted automatically 3 years after you unsubscribe.
10. Waitlist
The waitlists on this website let you be notified when new AYLEAN events or MYROX MATCH launch. The waitlists run on a shared waitlist service provided by our technical service provider. The following data are stored:
- Email address
- The consent text on which your sign-up is based
- Time of consent and of confirmation
- A hash of your email address (SHA-256)
Sign-up uses the double opt-in procedure: you receive a confirmation email with a confirmation link, and your sign-up only becomes effective once you click it. No browser identifier (user-agent) is stored. For abuse prevention (rate limiting), your IP address is not stored in plain text; it is processed solely as a SHA-256 hash and deleted automatically no later than 48 hours after it was collected (Art. 6(1)(f) GDPR — legitimate interest in preventing abuse). The data are stored in the database (see section "Database") and the emails are sent via the Resend service (see section "Email delivery").
Legal basis: Art. 6(1)(a) GDPR (consent).
Withdrawal: You can withdraw your consent at any time using the unsubscribe link contained in every email (Art. 7(3) GDPR). The unsubscribe link does not expire. When you withdraw, your email address is deleted immediately. To prevent an accidental repeat sign-up, the hash of your email address is kept. It is created without a random value ("salt") and is therefore pseudonymous, not anonymous: anyone who knows your email address can compute it and match it.
Retention period: Unconfirmed sign-ups are deleted automatically after 7 days; confirmed sign-ups are kept until you withdraw your consent. The hash of your email address is kept permanently after you unsubscribe.
11. Contact by email
If you contact us by email, the details you provide are stored by us to handle your enquiry and in case of follow-up questions. We do not pass these data on without your consent.
Our mailbox is operated by:
STRATO GmbH
Otto-Ostrowski-Straße 7
10249 Berlin, Germany
STRATO stores the emails you send us together with the data they contain (in particular email address, name and the content of the message). Emails to our former address info@ay-lean.com are processed by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with STRATO and with IONOS.
Legal basis: Art. 6(1)(b) GDPR if your enquiry relates to the performance of a contract or is necessary for pre-contractual measures; in all other cases Art. 6(1)(f) GDPR (legitimate interest in answering your enquiry).
Further information: STRATO Privacy Policy · IONOS DPA
12. Web analytics (currently not active)
This website currently uses no web analytics or tracking service (in particular no Vercel Analytics, Google Analytics or Plausible). Should such a service be introduced in future, this privacy policy will be updated accordingly beforehand.
13. Cookies and local storage
This website uses no tracking, marketing or analytics cookies and stores no data in your browser's local storage (localStorage).
If the language of the page you open differs from your browser's language setting, a cookie named NEXT_LOCALE is set. It contains only the chosen language (e.g. "de" or "en") so that the website keeps showing you that language. It is a session cookie and is deleted when you close your browser. In addition, hosting services may set short-lived, technically necessary cookies as part of their technical infrastructure. These cookies contain no personal data and are not used for advertising.
As only technically necessary storage is used, no consent is required under § 25(2) no. 2 TDDDG.
14. Your rights as a data subject
As a data subject, you have the following rights against the controller:
- Right of access (Art. 15 GDPR): you can request information about the personal data we process.
- Right to rectification (Art. 16 GDPR): you can request the correction of inaccurate or incomplete data.
- Right to erasure (Art. 17 GDPR): you can request the deletion of your data, unless statutory retention obligations apply.
- Right to restriction of processing (Art. 18 GDPR): you can request that processing be restricted under certain conditions.
- Right to data portability (Art. 20 GDPR): you can request your data in a structured, machine-readable format.
- Right to object (Art. 21 GDPR): you can object to the processing of your data where it is based on Art. 6(1)(f) GDPR (legitimate interest).
- Right to withdraw consent (Art. 7(3) GDPR): you can withdraw any consent you have given (e.g. for the newsletter or the waitlist) at any time with effect for the future.
To exercise your rights, please contact us by email: info@aylean.de. Requests are handled manually.
15. Right to lodge a complaint with a supervisory authority
Without prejudice to any other remedy, you have the right to lodge a complaint with the competent data protection supervisory authority:
Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5
30159 Hannover, Germany
Tel.: +49 (0) 511 120-4500
Email: poststelle@lfd.niedersachsen.de
Website: https://www.lfd.niedersachsen.de
16. Currency and changes
This privacy policy is current as of 7 October 2026. Further development of this website or changes in legal requirements may make updates necessary. The current version is always available at https://aylean.de/en/privacy.
Last updated: 7 October 2026