Back

Privacy policy machtfit Platform

This is an automated translation of our Privacy Policy for information purposes.

Privacy policy machtfit Platform

We are pleased about your visit and use of our machtfit platform. We regard the protection and security of your data as a very important part of our service. Therefore, we have designed our service in such a way that only the necessary personal data is collected or processed, with a clearly defined purpose for each. Our activities are exclusively focused on providing you with the best user experience and continuously improving it.

The personal data you provide or that is communicated to us by your employer is processed to provide our service, manage your bookings, and possibly for any requested service and support activities, as well as for the technical administration of the platform. Your personal data will not be used for any other purpose or shared with third parties.

This privacy statement explains which information we collect during your visit to our platform and how we process it.

Name and Contact Details of the Data Controller and Processor:

The provider and operator of the machtfit platform is:

machtfit GmbH
Monbijouplatz 5
10178 Berlin
Tel.: 030/34655060
E-Mail: datenschutz@machtfit.de

The provision of the platform and the associated processing of personal data is carried out for the entity through which you access our platform. This entity is the data controller according to Art. 4 No. 7 GDPR. We are the data processor in the sense of Art. 4 No. 8 GDPR.

We have appointed a data protection officer, who can be reached at the following contact details:

Robin Data GmbH
Fritz-Haber-Str. 9
06217 Merseburg
E-Mail: datenschutz@machtfit.de

Visiting the machtfit Platform

When you access our platform, the browser used on your device automatically sends information to the server of our platform. This information is temporarily stored in a log file. The following information is collected without your intervention and stored until automated deletion:

  • IP address of the requesting computer
  • Date and time of access
  • Name and URL of the accessed file
  • Website from which access is made (Referrer-URL)
  • Browser used and, if applicable, the operating system of your computer as well as the name of your Internet provider.

The processing of this data is based on the legitimate interest according to Art. 6 (1) S. 1 lit. f GDPR. The legitimate interest arises from ensuring the technical functionality of the platform.

For hosting the platform, we use the following service providers:

The log files are deleted after 30 days.

Cookies

This platform uses cookies. Cookies do not harm your computer and do not contain viruses. They are small text files stored on your computer and saved by your browser.

They serve the technical functionality of the platform and help us improve user-friendliness, effectiveness, and security.

To the extent that cookies serve the technical operation of the website and are essential for it, this constitutes a legitimate interest within the meaning of Art. 6 (1) S. 1 lit. f GDPR. Cookies that are not essential for the operation of the website are only set based on your consent according to Art. 6 (1) S. 1 lit. a GDPR.

For detailed information on the cookies used, particularly their deletion periods, please refer to the Cookie-Consent-Manager.

Types of Data Categories Processed

We distinguish between five categories of data:

(1) Functional data, without which the functionality of the platform would be limited.
(2) Data that you enter into the platform yourself.
(3) Optional data for analysis and customer service purposes.
(4) Data required exclusively when using an employer subsidy.
(5) Data transmitted exclusively when purchasing a service from a partner.

(1) Functional Data

To use our platform and receive services, you provide us with personal data, such as first and last name, email address, registration code, company affiliation, or location during registration (see table below). Data necessary for each process is marked as mandatory fields. Your email address serves as your username. We need the registration data to identify you as an employee of one of our customers, create and manage your user account, provide the contractual services, and contact you if necessary.

Depending on how your employer grants access rights, the processing of this data is based on your consent according to Art. 6 (1) S. 1 lit. A GDPR or for contract fulfillment accordingto Art. 6 (1) S. 1 lit. b GDPR.

Data Purpose Storage period
Registration details Creating a user account Until you unsubscribe from our platform.
Used offers Utilization and processing of offers Until unsubscription from our platform. At least 10 years for tax-privileged prevention offers.
Searched offers This information helps us to optimize and expand our offering and improve the user-friendliness of the platform. We can determine which offers are in particularly high demand and adapt our offer accordingly and show you similar offers. Until you unsubscribe from our platform.
Time and duration of use This enables us to determine at which times our services are used particularly intensively in order to optimize our technical equipment. Until you unsubscribe from our platform.
Time of the registration When you register, we store the time of your registration for billing purposes and for security reasons. Until you unsubscribe from our platform.
IP Address We collect and store this data for security reasons in order to prevent and, if necessary, trace cases of misuse of our services. The last three digits of the IP are anonymized and cannot be identified by machtfit. Until you deregister from our platform, but for a maximum of 1 year.
Name and version of your browser, browser plugins and operating system In the event of errors, e.g. in the display of the website or loading time, we can better determine the causes and implement improvements. It also tells us which browsers and systems we need to support. Until you deregister from our platform, but for a maximum of 1 year.
Session cookie When you log in, session cookies are used, which store a so-called session ID that can be used to assign various requests from your browser to the shared session. This means that you do not have to log in again every time you click on the website. The session cookies are deleted when you log out.

(2) Data You Enter into the Platform

To customize the available offers to your person, you have the option to provide additional data. These details are voluntary, so their processing only occurs with your consent according to Art. 6 (1) S. 1 lit. a GDPR.

Data Purpose Storage period
Your preferred search address If you wish, you can enter an address in your profile (e.g. your place of residence), which will be used to display offers in your vicinity Until you unsubscribe from our platform.
Type of your occupation (e.g. physical/non-physical/shift work) This information helps us to optimize and expand our offer and to improve the user-friendliness of the platform. In particular, your occupation tells us which offers might be of interest to you (e.g. shift workers are more likely to benefit from offers that do not take place on fixed dates). Until you unsubscribe from our platform.
Age This information helps us to optimize and expand our offering and to improve the user-friendliness of the platform. Based on your age, we can, for example, draw your attention to offers that are typically used by members of your age group. Until you unsubscribe from our platform.
Interests (e.g. training goals, product preferences, interest in health topics) This information helps us to optimize and expand our offering and to improve the user-friendliness of the platform. Based on your information, we can optimize and expand our offer according to your interests and needs. Until you unsubscribe from our platform.
Health perception (e.g. fitness level, stress perception, sleep quality) This information helps us to optimize and expand our offer. For example, we can use your details to draw your attention to offers that match your fitness level. Until you unsubscribe from our platform.
Offers saved as favorite We store this information so that you can find the offers you have saved as favorites at any time and on all devices. We can also send you matching offers. Until you unsubscribe from our platform.

(3) Optional Analysis Data (Cookies)

Optional analysis data for usage improvement serves the optimization and expansion of our offerings and the improvement of the platform's user-friendliness. The storage of optional analysis data only occurs after you have actively consented according to Art. 6 (1) S. 1 lit. a GDPR.

Below you can see the status of data recording. By clicking on it, you can deactivate or reactivate data collection:

We use a self-hosted open source machtfit analysis software to collect anonymous usage data for this website.

The behavior data is collected to identify possible issues such as not found pages, search engine problems, or unpopular pages. Once the data (number of visitors seeing error pages or only one page, etc.) is processed, the analysis software generates reports for the website operators to respond to.

The analysis software processes the following data:

  • Cookies
  • Anonymized IP addresses by removing the last 2 octets
  • Country, region, city (with low accuracy due to anonymized IP address)
  • Date and time of access
  • Title of the accessed page
  • URL of the accessed page
  • URL of the previous page (if allowed)
  • Screen resolution
  • Local time
  • Files clicked and downloaded
  • External links
  • Page load duration
  • Main language of the browser
  • Browser user agent
  • Interactions with forms (but not their content)

(4) Data Transmission to Your Employer

If your employer has agreed to subsidize the services you use, we transmit the necessary information to your employer for verification with tax authorities and billing purposes. The transmission of this information to your employer is required by law according to Art. 6 (1) S. 1 lit. c GDPR. Only the following necessary data will be transmitted:

  • Certificate of the utilized offer
  • Category of the offer (e.g., exercise)
  • Name of the offer for prevention programs
  • Participation confirmation for prevention programs (if participating)
  • Amount of the granted subsidy
  • Documents for reimbursement requests

Your employer has been instructed to use the data only for this defined purpose according to legal regulations.

machtfit provides the option to make internal health offers and health offers from third-party providers (e.g., corporate run organizers) available on the platform in addition to machtfit's health partners' offers. If your employer provides such offers on the platform, your employer or third-party providers have access to booking data for organizational reasons. This is necessary, for example, for rescheduling or room changes to inform you accordingly. This information is only made available to the persons responsible for the respective offer.

Beyond that, your employer does not receive any further information about your personal use of our offering.

(5) Data transmission to partners

If you make use of our partners’ services via the machtfit platform, we will send them the information relevant to the performance of the contract. This may include in particular:

  • First and last name
  • Your address
  • Email address
  • Service purchased
  • Confirmation of payment

Your data will only be passed on with your consent in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR.

If you make use of a discounted permanent service of a partner via our platform, we will inform this partner if you are no longer entitled to use the machtfit platform and thus the partner’s discounted offer.

The authorization basis for this is the legitimate interest pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR. The legitimate interest on the part of our partners is to prevent the unauthorized use of discounted services.

Infomail

To motivate the employees of our customers to engage in physical activity, your employer has commissioned us to send you regular tips to promote your health. The processing of your data for this purpose is based on legitimate interest according to Art. 6 (1) S. 1 lit. f GDPR. The legitimate interest arises from maintaining and promoting your health.

You can unsubscribe from this service or change its frequency at any time by clicking the link included in each mailing or by accessing the corresponding function in your user account.

We do not share your data with third parties for advertising purposes.

For mailings, we use the services of Emarsys eMarketing Systems GmbH, Lassallestraße 7b, 1020 Vienna, Austria. For more information about Emarsys' data protection, please refer to: https://www.emarsys.com/de/datenschutzrichtlinie/

machtfit Activity Challenges

Your employer has the option to offer a machtfit activity challenge through our platform, in which you can participate. When registering, you need to provide a „nickname“ (username) that is freely chosen. You can use an invented name or your real name. Throughout the activity challenge, other participants can see the names of team members before joining a team. Participants can also view the progress of other participants. Non-participants (viewers) can see the leaderboard after the activity challenge starts. During the challenge, you need to enter step results or physical activities. If you no longer wish to participate in the challenge, you can deregister at any time.

Participation in the activity challenge and providing a „nickname“ voluntary. By registering for participation, you (implicitly) consent to the associated data processing according to Art. 6 (1) S. 1 lit. a GDPR.

Anyone can see the names of team members before joining a team during the registration phase. Participants can view the progress of other participants. Non-participants (viewers) can see the leaderboard after the challenge starts.

During the activity challenge, email campaigns will inform you about interesting facts and events. You can unsubscribe from the email campaign at any time via a link at the end of each email.

As proof of participation, the employer can view the participant list in the administrator interface.

At the end of the activity challenge, all participants can voluntarily provide feedback. There may also be opportunities to win prizes provided by machtfit or your employer.

As participants in the activity challenge, you can also connect activity trackers (e.g., Fitbit, Google Fit, Apple Health) or your smartphone via iOS or Android with your machtfit user account.

To interface with a variety of devices, machtfit collaborates with mHealth Pioneers GmbH, whose Thryve service enables connections to many devices. Thryve can automatically transfer your data to machtfit, so you do not have to enter data manually. The interface between Thryve and your activity tracker or smartphone exists only as long as you wish. You can deactivate the interface at any time through the machtfit platform. After deactivating the interface, machtfit can no longer access your data from the activity tracker.

Contact and Support

If you send us a message via the contact details provided on our website, your contact details and any other personal data derived from the message will be processed by us for the purpose of handling the request. For processing email inquiries, we use the ticket system of Zammad GmbH, Marienstraße 18, 10117 Berlin, and Microsoft 365 from Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18 D18 P521. Further information on data protection at the mentioned service providers can be found below:

The personal data we process may include:

  • Salutation
  • First and last name
  • Email address
  • Content data

The processing of this data is based on your (implicit) consent according to Art. 6 (1) lit. a GDPR or on the basis of your legitimate interest according to Art. 6 (1) S. 1 lit. f GDPR. The legitimate interest lies in answering your questions and resolving issues.

Your Rights

You have the following rights regarding your personal data:

  • According to Art. 7 (3) GDPR, to withdraw consent once given at any time for the future;
  • According to Art. 15 GDPR, to request information about your processed personal data;
  • According to Art. 16 GDPR, to request the correction of incorrect or completion of your stored personal data;
  • According to Art. 17 GDPR, to request the deletion of your stored personal data, provided that the processing is not necessary for exercising the right to freedom of expression and information, for fulfilling a legal obligation, for reasons of public interest, or for asserting, exercising, or defending legal claims;
  • According to Art. 18 GDPR, to request the restriction of the processing of your personal data, provided that the accuracy of the data is disputed by you, the processing is unlawful, or you have objected to the processing according to Art. 21 GDPR;
  • According to Art. 20 GDPR, to receive your provided personal data in a structured, commonly used, and machine-readable format or to request the transfer to another responsible party;
  • According to Art. 21 GDPR, to object to the processing of your personal data, provided that the processing is based on a legitimate interest and there are reasons for the objection arising from your particular situation; and
  • According to Art. 77 GDPR, to lodge a complaint with a supervisory authority. The supervisory authority responsible for us is:
Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59-61
10555 Berlin
Telefon 030/13889-0
Telefax 030/2155050
E-Mail: mailbox@datenschutz-berlin.de

Status of the Privacy Policy: December 2024