Preamble
With the following Privacy Policy, we would like to inform you about the types of personal data (hereinafter also referred to as “data”) we process, the purposes for which we do so, and the scope of such processing. This Privacy Policy applies to all processing of personal data carried out by us, both in connection with the provision of our services and, in particular, on our websites, in mobile applications, and on external online platforms, such as our social media profiles (hereinafter collectively referred to as the “Online Offer”).
The terms used are not gender-specific.
As of June 27, 2026
Person in Charge
Wolfgang Zotter
21 Eichenweg
8572 Bärnbach
Authorized Representatives: Wolfgang
Email address: privacy@wozoria.at
Phone: 06644329490
Legal Notice: https://www.wozoria.at/impressum.html
Overview of Processing Steps
The following overview summarizes the types of data processed and the purposes of such processing, and identifies the data subjects.
Types of Data Processed
- Inventory data.
- Employee data.
- Payment information.
- Location data.
- Contact Information.
- Table of Contents.
- Contract information.
- Usage data.
- Meta data, communication data, and procedural data.
- Log data.
- Member Information.
Categories of Data Subjects
- Service recipients and clients.
- Employees.
- Prospective buyers.
- Communication partners.
- Users.
- Members.
- Business and contractual partners.
- Third parties.
- Whistleblower.
Purposes of Processing
- Provision of contractual services and fulfillment of contractual obligations.
- Communication.
- Safety measures.
- Range measurement.
- Tracking.
- Office and Organizational Procedures.
- Conversion Tracking.
- Target Audience Identification.
- Affiliate Tracking.
- Organizational and Administrative Procedures.
- Feedback.
- Marketing.
- Profiles containing user-specific information.
- Registration Process.
- Provision of our online services and user-friendliness.
- Information Technology Infrastructure.
- Public relations and informational purposes.
- Whistleblower Protection.
- Business processes and management practices.
Relevant Legal Bases
Relevant legal bases under the GDPR: Below is an overview of the legal bases under the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your country of residence or our country of residence or registered office. If, in individual cases, more specific legal bases apply, we will inform you of these in the Privacy Policy.
- Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR) - The data subject has given consent to the processing of personal data concerning him or her for a specific purpose or for several specific purposes.
- Performance of a Contract and Pre-Contractual Inquiries (Art. 6(1), first sentence, subparagraph (b) of the GDPR) - The processing is necessary for the performance of a contract to which the data subject is a party, or for the implementation of precontractual measures taken at the data subject’s request.
- Legal obligation (Art. 6(1), first sentence, subparagraph (c) of the GDPR) - The processing is necessary to comply with a legal obligation to which the controller is subject.
- Legitimate Interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR) - The processing is necessary to safeguard the legitimate interests of the controller or a third party, provided that the interests, fundamental rights, and fundamental freedoms of the data subject that require the protection of personal data do not take precedence.
- Membership Agreement (Bylaws) (Art. 6(1), sentence 1, subparagraph (b) of the GDPR).
National Data Protection Regulations in Austria: In addition to the data protection provisions of the GDPR, national data protection regulations apply in Austria. These include, in particular, the Federal Act on the Protection of Natural Persons with Regard to the Processing of Personal Data (Data Protection Act—DSG). The Data Protection Act contains, in particular, specific provisions regarding the right of access, the right to rectification or erasure, the processing of special categories of personal data, processing for other purposes, data transfers, and automated decision-making in individual cases.
Note on the applicability of the GDPR and the Swiss Data Protection Act (DSG): This privacy notice serves to provide information in accordance with both the Swiss Data Protection Act (DSG) and the General Data Protection Regulation (GDPR). For this reason, please note that, due to the GDPR’s broader geographical scope and greater clarity, the terms used in the GDPR are employed here. In particular, instead of the terms “processing” of “personal data,” “overriding interest,” and “personal data requiring special protection,” we use the terms “processing” of “personal data,” as well as “legitimate interest” and “special categories of data” as defined in the GDPR. However, the legal meaning of these terms continues to be determined in accordance with the Swiss Data Protection Act (DSG) within the scope of its applicability.
Applicability of Data Protection Regulations in the Country of Incorporation: In the country where the controller is established, national data protection regulations apply in addition to the General Data Protection Regulation (GDPR).
Safety Measures
We implement technical and organizational measures appropriate to the circumstances and the purposes of the processing, as well as the varying likelihoods and severity of threats to the rights and freedoms of natural persons, in accordance with legal requirements and taking into account the state of the art, the costs of implementation, and the nature, scope, circumstances, and purposes of the processing, as well as the varying likelihoods and severity of threats to the rights and freedoms of natural persons, to ensure a level of protection appropriate to the risk.
These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data, as well as access to, input of, and disclosure of the data, ensuring its availability, and maintaining its separation. Furthermore, we have established procedures that ensure the exercise of data subjects’ rights, the deletion of data, and responses to data breaches. Furthermore, we take the protection of personal data into account from the very beginning of the development or selection of hardware, software, and procedures, in accordance with the principle of data protection through technical design and privacy-friendly default settings.
Securing Online Connections Using TLS/SSL Encryption Technology (HTTPS): To protect user data transmitted via our online services from unauthorized access, we rely on TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the Internet. These technologies encrypt the information transmitted between the website or app and the user’s browser (or between two servers), thereby protecting the data from unauthorized access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is indicated by the presence of “HTTPS” in the URL. This serves as an indicator to users that their data is being transmitted securely and in an encrypted form.
Firebase & Google Cloud Database Services
We use Google Firebase (a cloud service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) as the technical foundation for the database, authentication, and hosting. Firebase is part of the Google Cloud Platform and is subject to strict data protection and security standards.
Password Security & Encrypted Storage
Passwords are never stored in plain text. Authentication is performed exclusively via Firebase Authentication, which encrypts passwords internally using scrypt (a secure cryptographic hashing algorithm with a unique salt for each user). Neither the platform operator nor club administrators have access to plaintext passwords—these are unreadable even to database administrators. Even full database access would not reveal any passwords.
Database Access & Security Rules
Access to the cloud database (Firestore) is provided by Firestore Security Rules Technically restricted. Every database access requires a valid, active login. Direct access to the database from outside the system without authentication is technically impossible. Even the platform operator can only view club data as part of a documented support case and not on a routine basis.
Graduated Visibility: The security rules determine who is allowed to view which data. Information requiring special protection—coach observations, notes about a person, and performance metrics—is accessible exclusively to coaches and club administrators. Players and parents/guardians can only view data for the person assigned to them or their own child, not that of other club members. This restriction is enforced within the database itself, not just in the application’s interface.
Data Storage Location
Data is stored on Firebase servers in the region Western Europe (EU) stored to comply with the GDPR's requirements regarding data storage location. All data is transmitted exclusively via TLS-encrypted connections (HTTPS).
- Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
- Privacy Policy: https://business.safety.google/privacy/
- Basis for Transfers to Third Countries: Data Privacy Framework (DPF), Standard Contractual Clauses
- Legal Basis: Performance of a contract (Art. 6(1), first sentence, subparagraph (b) of the GDPR); Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
Transfer of Personal Data
As part of our processing of personal data, it may occur that such data is transferred to or disclosed to other entities, companies, legally independent organizational units, or individuals. Recipients of this data may include, for example, service providers contracted to perform IT tasks or providers of services and content integrated into a website. In such cases, we comply with legal requirements and, in particular, enter into appropriate contracts or agreements with the recipients of your data to ensure the protection of your data.
International Data Transfers
Data Processing in Third Countries: If we transfer data to a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)) or if this occurs in connection with the use of third-party services or the disclosure or transfer of data to other individuals, entities, or companies (which can be identified by the postal address of the respective provider or if the privacy policy expressly refers to data transfers to third countries), this is always done in accordance with legal requirements.
For data transfers to the United States, we primarily rely on the Data Privacy Framework (DPF), which was recognized as a secure legal framework by an adequacy decision of the European Commission dated July 10, 2023. In addition, we have entered into standard contractual clauses with the respective providers that comply with the European Commission’s requirements and establish contractual obligations to protect your data.
This two-tiered safeguard ensures comprehensive protection of your data: The DPF serves as the primary layer of protection, while the Standard Contractual Clauses provide an additional layer of security. Should any changes arise within the scope of the DPF, the Standard Contractual Clauses will serve as a reliable fallback option. This ensures that your data remains adequately protected at all times, even in the event of any political or legal changes.
For each service provider, we will let you know whether they are DPF-certified and whether standard contract clauses are in place. For more information on the DPF and a list of certified companies, please visit the U.S. Department of Commerce website at https://www.dataprivacyframework.gov/ (in English).
Appropriate security measures apply to data transfers to other third countries, in particular standard contractual clauses, explicit consent, or transfers required by law. Information on transfers to third countries and applicable adequacy decisions can be found on the European Commission’s website: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.
General Information on Data Storage and Deletion
We delete the personal data we process in accordance with legal requirements as soon as the underlying consents are revoked or there is no longer a legal basis for processing. This applies to cases in which the original purpose of processing no longer applies or the data is no longer needed. Exceptions to this rule apply when legal obligations or specific interests require the data to be retained or archived for a longer period.
In particular, data that must be retained for commercial or tax law purposes, or whose storage is necessary for the enforcement of legal claims or the protection of the rights of other natural or legal persons, must be archived accordingly.
Our privacy policy contains additional information regarding the retention and deletion of data that applies specifically to certain processing operations.
If there are multiple specifications regarding the retention period or deletion deadlines for a particular piece of data, the longest period shall always apply. We process data that is no longer retained for its originally intended purpose—but rather due to legal requirements or other reasons—exclusively for the purposes that justify its retention.
Start of the Time Period at the End of the Year: If a time period does not expressly begin on a specific date and is at least one year in duration, it automatically begins at the end of the calendar year in which the event triggering the time period occurred. In the case of ongoing contractual relationships under which data is stored, the event triggering the time limit is the date on which the termination or other termination of the legal relationship takes effect.
Deletion Process for Player, Member, and Media Data (Archiving, Retention, Permanent Deletion)
A multi-step deletion process applies to the personal data of players and members, including any associated photos and videos:
- Archiving: If an authorized user (club administrator) deletes a record, it is initially only archived. Archived records are no longer displayed in the current application and can be restored at any time.
- Deletion flag: An archived record can be permanently deleted noted ... A retention period of eight (8) weeks begins at that time. The data record can still be restored within this period.
- Automatic permanent deletion: Once the eight-week period has expired, the data set, along with all associated photos and videos, will be automatically and permanently deleted from the system and the media server. Once the data has been permanently deleted, it will no longer be possible to access or recover it.
Immediate deletion by the system administrator: The system administrator can permanently delete an archived record or one marked for deletion at any time—even immediately, before the deadline expires—including any associated photos and videos.
Early Deletion Upon Request: Data subjects or their legal guardians may immediate Request in writing that your data be deleted before the retention period expires. In this case, the data will be permanently deleted without delay; the data record and all associated media will also be irrevocably removed.
Orders are anonymized rather than deleted: Orders from the club store are retained as business records because they are subject to legal retention requirements. Therefore, when a person’s account is permanently deleted, they are anonymized: The recipient's name is replaced with "N/V," and all names entered for customization (printing on textiles) are removed. Only the item, size, quantity, and, if applicable, the jersey number remain—with no reference to a specific person.
Performance measurements: Recorded data (e.g., sprint times, technical drills) is completely deleted when a person’s account is permanently deleted. As long as this data remains, it is accessible only to coaches and club administrators, as well as to the person concerned or their legal guardians—not to other club members.
Rights of Data Subjects
Rights of Data Subjects Under the GDPR: As a data subject, you have various rights under the GDPR, which arise in particular from Articles 15 through 21 of the GDPR:
- Right to Object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data carried out pursuant to Article 6(1)(e) or (f) of the GDPR; this also applies to profiling based on these provisions. If your personal data is processed for the purpose of direct marketing, you have the right to object at any time to the processing of your personal data for such marketing purposes; this also applies to profiling to the extent that it is related to such direct marketing.
- Right to Withdraw Consent: You have the right to withdraw any consent you have given at any time.
- Right to Information: You have the right to request confirmation as to whether the relevant data is being processed, as well as access to that data, additional information, and a copy of the data in accordance with legal requirements.
- Right to Correction: In accordance with legal requirements, you have the right to request that the data concerning you be completed or that any inaccurate data concerning you be corrected.
- Right to erasure and restriction of processing: In accordance with legal requirements, you have the right to request that data concerning you be deleted immediately or, alternatively, to request that the processing of such data be restricted in accordance with legal requirements.
- Right to Data Portability: You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, in accordance with legal requirements, or to request that it be transferred to another data controller.
- Complaint to the regulatory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work, or the location of the alleged infringement, if you believe that the processing of your personal data violates the provisions of the GDPR.
Performance of duties in accordance with the bylaws or rules of procedure
We process the data of our members, supporters, prospective members, business partners, or other individuals (collectively, “data subjects”) when we have a membership or other business relationship with them, when we carry out our duties, and when they are recipients of services and benefits. In addition, we process the data of data subjects based on our legitimate interests, e.g., in connection with administrative tasks or public relations activities.
The data processed in this context, as well as the nature, scope, purpose, and necessity of its processing, are determined by the underlying membership or contractual relationship, which also dictates the necessity of providing any data (we will, incidentally, indicate which data is required).
We delete data that is no longer necessary for the fulfillment of our statutory and business purposes. This is determined based on the respective tasks and contractual relationships. We retain data for as long as it may be relevant for business transactions, as well as with regard to any warranty or liability obligations, based on our legitimate interest in addressing such matters. The necessity of retaining the data is reviewed on a regular basis; otherwise, statutory retention requirements apply.
- Types of Data Processed: Master data (e.g., full name, home address, contact information, customer number, etc.); contact information (e.g., mailing and email addresses or phone numbers); contract data (e.g., subject matter of the contract, term, customer category); Membership data (e.g., personal data such as name, age, gender, contact information (email address, phone number), membership number, information about membership dues, participation in events, etc.); payment data (e.g., bank account information, invoices, payment history). Content data (e.g., text or image-based messages and posts, as well as related information, such as details regarding authorship or the time of creation).
- Affected individuals: Members; Prospective Members; Communication Partners.
- Purposes of processing and legitimate interests: Communication; organizational and administrative procedures; public relations and informational purposes. Business processes and business management procedures.
- Retention and Deletion: Deletion in accordance with the information provided in the section "General Information on Data Storage and Deletion."
- Legal Basis: Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR); Membership agreement (Articles of Association) (Art. 6(1), first sentence, subparagraph (b) of the GDPR). Legal obligation (Art. 6(1), first sentence, subparagraph (c) of the GDPR).
Additional information on processing procedures, methods, and services:
- Member Management: Processes required for membership management include recruiting and enrolling new members, developing and implementing strategies for member retention, and ensuring effective communication with members. These processes involve the careful collection and maintenance of member data, the regular updating of member information, and the management of membership dues, including billing and accounting; Legal Basis: Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR), membership agreement (bylaws) (Art. 6(1), first sentence, subparagraph (b) of the GDPR).
- Contribution Management: The processing activities required for the administration of membership dues include the collection of membership dues data after a member joins, tracking membership fee payments and systematically updating payment status, processing payment transactions, issuing reminders for overdue payments, reconciling accounts in the context of receivables and payables, and maintaining the corresponding books and records; Legal Basis: Legal obligation (Art. 6(1), first sentence, subparagraph (c) of the GDPR), legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR), membership agreement (Articles of Association) (Art. 6(1), first sentence, subparagraph (b) of the GDPR).
- Events and Organizational Operations: Planning, execution, and follow-up of events, as well as the general operation of activities specified in the bylaws. Planning involves collecting and processing participant data, coordinating logistical requirements, and setting the event agenda. Execution includes managing participant registration, updating participant information during the event, and tracking attendance and participant activities. Follow-up includes analyzing participant data to evaluate the event’s success, preparing reports, and archiving relevant information about the event. General organizational operations include managing member data, communicating with members and prospective members, and organizing internal meetings and sessions; Legal Basis: Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR), membership agreement (bylaws) (Art. 6(1), first sentence, subparagraph (b) of the GDPR).
- Public Relations: These activities include the creation and distribution of informational materials, the maintenance of contact information for press and media relations, and the organization and conduct of press conferences and public events. Interaction with the media and stakeholders takes place through direct communication with journalists, bloggers, and other opinion leaders, responding to inquiries, and providing information; Legal Basis: Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR), membership agreement (bylaws) (Art. 6(1), first sentence, subparagraph (b) of the GDPR).
Business Services
We process the personal data of our contractual and business partners—such as customers, clients, prospective customers, suppliers, and other business partners (collectively, “Contractual Partners”)—for the purpose of initiating, executing, and fulfilling contractual relationships and similar legal relationships. This also includes pre-contractual measures taken upon request, as well as communication related to the respective contractual relationship.
The processing is intended, in particular, to fulfill our primary and secondary contractual obligations. These include the provision of the agreed-upon services, any obligations to provide updates and information, the handling of warranty claims and other service disruptions, the processing of cancellations, terminations of continuing contractual relationships, rescissions, refunds, and the processing of other contract-related declarations and inquiries. This covers both one-time contracts and ongoing contractual relationships.
- Types of Data Processed: Master data (e.g., full name, home address, contact information, customer number, etc.); payment data (e.g., bank account information, invoices, payment history); contact information (e.g., mailing and email addresses or phone numbers). Contract data (e.g., subject matter of the contract, term, customer category).
- Affected individuals: Service recipients and clients; prospective clients. Business and contractual partners.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfillment of contractual obligations; communication; office and organizational procedures; organizational and administrative procedures. Business processes and business management procedures.
- Retention and Deletion: Deletion in accordance with the information provided in the section "General Information on Data Storage and Deletion."
- Legal Basis: Performance of a contract and pre-contractual inquiries (Art. 6(1), first sentence, lit. b) of the GDPR); Legal obligation (Art. 6(1), first sentence, lit. c) of the GDPR). Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
Provision of the Online Service and Web Hosting
We process users' data in order to provide them with our online services. For this purpose, we process the user's IP address, which is necessary to deliver the content and features of our online services to the user's browser or device.
- Types of Data Processed: Usage data (e.g., page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and features); Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, individuals involved). Log data (e.g., log files regarding logins, data retrieval, or access times).
- Affected individuals: Users (e.g., website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online services and user-friendliness; IT infrastructure (operation and provision of information systems and technical equipment (computers, servers, etc.)). Security measures.
- Retention and Deletion: Deletion in accordance with the information provided in the section "General Information on Data Storage and Deletion."
- Legal Basis: Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
Additional information on processing procedures, methods, and services:
- Hosting an online service on rented server space: To provide our online services, we use storage space, computing capacity, and software that we rent or otherwise obtain from a server provider (also known as a "web host"); Legal Basis: Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
- Collection of access data and log files: Access to our online services is logged in the form of so-called "server log files." Server log files may include the address and name of the web pages and files accessed, the date and time of the request, the amount of data transferred, a notification of a successful request, the browser type and version, the user’s operating system, the referrer URL (the previously visited page), and, as a rule, IP addresses and the requesting provider. The server log files may be used, on the one hand, for security purposes—for example, to prevent server overload (particularly in the event of malicious attacks, known as DDoS attacks)—and, on the other hand, to ensure server capacity and stability; Legal Basis: Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR). Deletion of Data: Log file information is stored for a maximum of 30 days and is then deleted or anonymized. Data that must be retained for evidentiary purposes is exempt from deletion until the incident in question has been fully resolved.
Use of Cookies
The term “cookies” refers to functions that store and retrieve information on users’ devices. Cookies may also be used for various purposes, such as ensuring the functionality, security, and convenience of online services, as well as analyzing visitor traffic. We use cookies in accordance with legal requirements. To this end, we obtain users’ consent in advance when necessary. If consent is not required, we rely on our legitimate interests. This applies when the storage and retrieval of information is essential to provide explicitly requested content and functions.
Information on the Legal Basis for Data Protection: Whether we process personal data using cookies depends on consent. If consent has been given, it serves as the legal basis. Without consent, we rely on our legitimate interests, which are explained earlier in this section and in the context of the respective services and procedures.
Retention period: With regard to storage duration, the following types of cookies are distinguished:
- Temporary cookies (also known as session cookies): Temporary cookies are deleted at the latest after a user leaves an online service and closes their device (e.g., browser or mobile app).
- Persistent cookies: Persistent cookies remain stored even after the device is turned off. This allows, for example, the user’s login status to be saved and preferred content to be displayed immediately when the user revisits a website. Similarly, user data collected via cookies may be used for audience measurement. Unless we provide users with explicit information regarding the type and storage duration of cookies (e.g., when obtaining consent), they should assume that these cookies are persistent and may be stored for up to two years.
General Information on Withdrawal and Opt-Out: Users may revoke the consents they have provided at any time and may also object to the processing of their data in accordance with legal requirements, including through their browser's privacy settings.
- Types of Data Processed: Meta data, communication data, and transaction data (e.g., IP addresses, timestamps, identification numbers, individuals involved).
- Affected individuals: Users (e.g., website visitors, users of online services).
- Legal Basis: Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR). Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR).
Registration, Login, and User Account
Users can create a user account. During registration, users are informed of the required mandatory information, which is processed for the purpose of providing the user account based on the fulfillment of contractual obligations. The data processed includes, in particular, login information (username, password, and an email address).
When you use our registration and login functions, as well as your user account, we store your IP address and the time of each user action. This data is stored based on our legitimate interests, as well as those of our users, in protecting against misuse and other unauthorized use. We do not disclose this data to third parties under any circumstances, unless it is necessary to pursue our claims or we are legally obligated to do so.
Users may be notified via email about matters relevant to their user accounts, such as technical changes.
- Types of Data Processed: Master data; contact information; content data; usage data; log data.
- Affected individuals: Users (e.g., website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of contractual services and fulfillment of contractual obligations; security measures; organizational and administrative procedures. Provision of our online services and user-friendliness.
- Retention and Deletion: Deletion in accordance with the information provided in the section "General Information on Data Storage and Deletion." Deletion upon termination.
- Legal Basis: Contract performance and pre-contractual inquiries (Art. 6(1), first sentence, subparagraph (b) of the GDPR). Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
Additional information on processing procedures, methods, and services:
- Registration using your real name: Given the nature of our community, we ask users to use our service only under their real names. This means that the use of pseudonyms is not permitted; Legal Basis: Performance of a contract and pre-contractual inquiries (Art. 6(1), first sentence, subparagraph (b) of the GDPR).
- Deletion of Data Following Termination: If users have closed their user accounts, their data related to those accounts will be deleted, subject to any legal authorization, obligation, or consent from the users; Legal Basis: Performance of a contract and pre-contractual inquiries (Art. 6(1), first sentence, subparagraph (b) of the GDPR).
- No obligation to retain data: It is the users’ responsibility to back up their data upon termination prior to the end of the contract. We are entitled to permanently delete all of the user’s data stored during the term of the contract; Legal Basis: Performance of a contract and pre-contractual inquiries (Art. 6(1), first sentence, subparagraph (b) of the GDPR).
Minors & Parental Consent
As club management software, Wozoria Sports OS is aimed in particular at teenagers and children aged 10 years. In accordance with Article 8 of the GDPR, the Consent of Legal Guardians required.
Registration of Minors
By actively accepting the Terms and Conditions during registration, parents or guardians confirm that they:
- Have read and understood the privacy policy in its entirety.
- Agree to the child's use of the app.
- Agree to have the child's sports data (training sessions, game statistics, performance metrics) stored in the system.
- Agree to allow coaches and authorized club officials to review club records.
Special Protection for Minors' Data
- Data from minors is not used for advertising purposes.
- Data from minors is Not sold to third parties — This applies without exception.
- Anonymized, aggregated use of development data (e.g., average training progress for an age group) for system development is permitted; no individuals are identified in the process.
- Legal guardians may request information about their child's stored data at any time and may request that it be completely deleted.
- Legal Basis: Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR); Art. 8 of the GDPR (Consent for Children).
Terms and Conditions, Terms of Use, and Consent Upon Registration
During registration, users (or their legal guardians) are actively asked to agree to the Terms of Use. Registration is not possible without consent. Consent includes:
What Is Subject to Approval
- Profile and Contact Information: Storage of name, email address, and club affiliation.
- Performance Specifications: Saving training sessions, game statistics, performance metrics, XP points, and badges.
- Image data: Profile photos, if uploaded by the user (optional; can be deleted at any time).
- Visibility within the club: Profile and performance data are available to coaches and authorized club officials.
- Technical implementation by Firebase (Google Cloud): Storage and processing of all data on the Firebase platform (for details, see the section Firebase & Google Cloud).
Rejection of the Terms and Conditions & Right to Erasure
Use of Wozoria Sports OS requires acceptance of the Terms and Conditions. If a user rejects the Terms and Conditions or revokes their acceptance at a later date, the full Deletion of All Stored Personal Data may be requested:
- Change of Clubs: When leaving a club, you can request that your data be deleted from the club administrator or directly from the platform operator.
- Withdrawal of Consent: You may revoke your consent at any time, which will result in the deletion of your user account and all associated personal data within 30 days.
- Exceptions: Anonymized statistics that do not contain any personal information may remain in aggregated form after deletion.
The platform operator reserves all rights to the platform, the source code, and the system design. User data remains the property of the users and the association.
- Legal Basis: Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR); performance of a contract (Art. 6(1), first sentence, subparagraph (b) of the GDPR).
Internal Club Access Roles
Wozoria Sports OS has clearly defined access levels. Access to personal data is governed by the Principle of Least Privilege Technically governed by Firestore Security Rules.
- SuperAdmin (Platform Operator): Technical maintenance and platform support. No routine access to club data; data access is permitted only in documented support cases.
- Admin (Club Director): Full access to all data related to your own club (players, practices, members, finances).
- Coach: Access to player, practice, and game data for the assigned team, as well as attendance lists.
- Youth Leader: Access to your own team's roster and practice schedules; limited access to performance data.
- Player/Member: Access is limited exclusively to your own profile and performance data.
- Guest: Limited demo access without access to real personal data.
Unauthorized access to data from other clubs or to user data outside one's own role is technically prevented by Firestore Security Rules.
- Legal Basis: Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR); performance of a contract (Art. 6(1), first sentence, subparagraph (b) of the GDPR).
Anonymous Data Export & Development
To ensure the quality and further development of Wozoria Sports OS, the platform operator may exclusively anonymized and aggregated Use data. The following applies:
- The following will be No personal data (Name, email, player ID) exported or used for development purposes.
- Only statistical aggregates are factored into further development (e.g., "average number of training sessions per season").
- Data from minors is exclusively in an anonymized, non-traceable form used — it is technically impossible to identify individuals.
- No information will be disclosed to third parties.
- The platform operator agrees to protect children's data Never sell for commercial purposes or to use for marketing purposes.
- Legal Basis: Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
Community Features
The community features we provide allow users to engage in conversations or otherwise interact with one another. Please note that use of the community features is permitted only in compliance with applicable law, our terms and policies, and the rights of other users and third parties.
- Types of Data Processed: Personal information (e.g., full name, home address, contact information, customer number, etc.). Usage data (e.g., page views and time spent on the site, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and features).
- Affected individuals: Users (e.g., website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of contractual services and fulfillment of contractual obligations; security measures. Provision of our online services and user-friendliness.
- Retention and Deletion: Deletion in accordance with the information provided in the section "General Information on Data Storage and Deletion."
- Legal Basis: Contract performance and pre-contractual inquiries (Art. 6(1), first sentence, subparagraph (b) of the GDPR). Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
Additional information on processing procedures, methods, and services:
- Right to Have Content and Information Deleted: The deletion of user posts, content, or information is permitted to the extent necessary, following a proper assessment, provided there are concrete indications that they constitute a violation of legal regulations, our guidelines, or the rights of third parties; Legal Basis: Performance of a contract and pre-contractual inquiries (Art. 6(1), first sentence, subparagraph (b) of the GDPR).
- Protecting Your Own Data: Users decide for themselves what information they disclose about themselves within our online platform. For example, when users provide personal information or participate in conversations. We ask users to protect their data and to disclose personal information only with caution and only to the extent necessary. In particular, we ask users to note that they must take special care to protect their login credentials and use secure passwords (i.e., primarily combinations of characters that are as long and random as possible); Legal Basis: Performance of a contract and pre-contractual inquiries (Art. 6(1), first sentence, subparagraph (b) of the GDPR).
Single Sign-On Login
The terms "single sign-on," "single sign-on login," or "single sign-on authentication" refer to procedures that allow users to log in to our online services using a single user account with a single sign-on provider (e.g., a social network), to also log in to our online service. A prerequisite for single sign-on authentication is that users are registered with the respective single sign-on provider and enter the required login credentials in the designated online form, or are already logged in with the single sign-and confirm the single sign-on login by clicking the button.
Authentication takes place directly with the respective single sign-on provider. As part of this authentication process, we receive a user ID indicating that the user is logged in to the respective single sign-on provider under that user ID, as well as an ID (known as a “user handle”) that we cannot use for any other purposes. Whether additional data is transmitted to us depends solely on the single sign-on method used, the data sharing options selected during authentication, and also on which data users have made available in the privacyor other settings of the user account with the single sign-on provider. Depending on the single sign-on provider and the user’s choices, this may include various data; typically, it consists of the email address and username. We cannot view the password entered as part of the single sign-on process with the single sign-on provider, nor do we store it.
Users are asked to note that the information we have on file for them may be automatically synchronized with their user account at the single sign-on provider; however, this is not always possible or actually done. If, for example, a user’s email address changes, they must update it manually in their user account with us.
We may use single sign-on authentication, provided this has been agreed upon with the users, either during or prior to the performance of the contract, provided that users have been asked to consent to such processing; otherwise, we use it based on our legitimate interests and the users’ interests in an effective and secure login system.
If users ever decide they no longer wish to use the link between their user account and the single sign-on provider for the single sign-on process, they must disconnect this link within their user account with the single sign-on provider. If users wish to have their data deleted from our system, they must cancel their registration with us.
- Types of Data Processed: Master data (e.g., full name, home address, contact information, customer number, etc.); contact information (e.g., mailing and email addresses or phone numbers); Usage data (e.g., page views and time spent on the site, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and features). Meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, individuals involved).
- Affected individuals: Users (e.g., website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of contractual services and fulfillment of contractual obligations; security measures; registration procedures. Provision of our online services and user-friendliness.
- Retention and Deletion: Deletion in accordance with the information provided in the section "General Information on Data Storage and Deletion." Deletion upon termination.
- Legal Basis: Contract performance and pre-contractual inquiries (Art. 6(1), first sentence, subparagraph (b) of the GDPR). Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
Additional information on processing procedures, methods, and services:
- Google Single Sign-On: Authentication services for user logins, provision of single sign-on capabilities, management of identity information, and application integrations; Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal Basis: Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR); Website: https://www.google.de; Privacy Policy: https://business.safety.google/privacy/; Basis for Transfers to Third Countries: Data Privacy Framework (DPF). Right to Opt Out: Settings for displaying ads: https://myadcenter.google.com/.
Contact and Inquiry Management
When you contact us (e.g., by mail, contact form, email, phone, or social media), as well as in the context of existing user and business relationships, we process the information provided by the individuals making the inquiry to the extent necessary to respond to their inquiries and take any requested actions.
- Types of Data Processed: Contact information (e.g., mailing and email addresses or phone numbers); content data (e.g., text or image-based messages and posts, as well as related information such as details regarding authorship or the time of creation). Meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, and individuals involved).
- Affected individuals: Communication partners.
- Purposes of processing and legitimate interests: Communication; organizational and administrative procedures; feedback (e.g., collecting feedback via an online form). Provision of our online services and user-friendliness.
- Retention and Deletion: Deletion in accordance with the information provided in the section "General Information on Data Storage and Deletion."
- Legal Basis: Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR). Performance of a contract and pre-contractual inquiries (Art. 6(1), first sentence, subparagraph (b) of the GDPR).
Additional information on processing procedures, methods, and services:
- Contact Form: When you contact us via our contact form, by email, or through other communication channels, we process the personal data you provide to us in order to respond to and handle your inquiry. This generally includes information such as your name, contact information, and, if applicable, any additional information provided to us that is necessary for proper processing. We use this data exclusively for the stated purpose of establishing contact and communication; Legal Basis: Performance of a contract and pre-contractual inquiries (Art. 6(1), first sentence, subparagraph (b) of the GDPR), legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
Web Analytics, Monitoring, and Optimization
Web analytics (also referred to as “reach measurement”) is used to analyze visitor traffic to our online platform and may include pseudonymized data on visitor behavior, interests, or demographic information—such as age or gender. With the help of audience measurement, we can, for example, determine at what times our online platform or its features and content are used most frequently, or encourage repeat visits. It also allows us to identify which areas require optimization.
In addition to web analytics, we can also use testing methods to, for example, test and optimize different versions of our online offering or its components.
Unless otherwise specified below, profiles—that is, data aggregated for a specific usage session—may be created for these purposes, and information may be stored in a browser or on a device and then retrieved. The information collected includes, in particular, websites visited and elements used on those sites, as well as technical information such as the browser used, the computer system used, and details regarding usage times. If users have consented to the collection of their location data by us or by the providers of the services we use, the processing of location data is also possible.
In addition, users’ IP addresses are stored. However, we use an IP masking method (i.e., pseudonymization by truncating the IP address) to protect users. In general, no personally identifiable user data (such as email addresses or names) is stored in the context of web analytics, A/B testing, and optimization; instead, pseudonyms are used. This means that neither we nor the providers of the software we use know the actual identity of the users, but only the information stored in their profiles for the purpose of the respective processes.
Notes on Legal Bases: If we ask users for their consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, user data is processed based on our legitimate interests (i.e., our interest in providing efficient, cost-effective, and user-friendly services). In this context, we would also like to draw your attention to the information regarding the use of cookies in this Privacy Policy.
- Types of Data Processed: Usage data (e.g., page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and features). Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, individuals involved).
- Affected individuals: Users (e.g., website visitors, users of online services).
- Purposes of processing and legitimate interests: Audience measurement (e.g., traffic statistics, identification of returning visitors); profiles containing user-specific information (creation of user profiles); provision of our online services and user-friendliness.
- Safety Measures: IP masking (pseudonymization of the IP address).
- Legal Basis: Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR). Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
Additional information on processing procedures, methods, and services:
- Google Analytics: We use Google Analytics to measure and analyze the use of our online service based on a pseudonymous user identification number. This identification number does not contain any unique data, such as names or email addresses. It is used to associate analytical information with a device in order to determine which content users have accessed during one or more sessions, which search terms they have used, whether they have revisited that content, or how they have interacted with our online service. The time of use and its duration are also stored, as well as the sources from which users were referred to our online service and technical aspects of their devices and browsers. In doing so, pseudonymous user profiles are created using information from the use of various devices, and cookies may be used for this purpose. Google Analytics does not log or store individual IP addresses for EU users. However, Analytics provides rough geographic location data by deriving the following metadata from IP addresses: city (and the derived latitude and longitude of the city), continent, country, region, subcontinent (and ID-based equivalents). For EU data traffic, IP address data is used exclusively for this derivation of geolocation data before being immediately deleted; Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal Basis: Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR); Website: https://marketingplatform.google.com/intl/de/about/analytics/; Safety Measures: IP masking (pseudonymization of the IP address); Privacy Policy: https://business.safety.google/privacy/; Basis for Transfers to Third Countries: Data Privacy Framework (DPF), Standard Contractual Clauses (https://business.safety.google/adsprocessorterms); Right to Opt Out: Opt-Out Plugin: https://tools.google.com/dlpage/gaoptout?hl=de, Settings for displaying ads: https://myadcenter.google.com/personalizationoff.
Online Marketing
We process personal data for the purpose of online marketing, which may include, in particular, the marketing of advertising space or the display of advertising and other content (collectively referred to as “Content”) based on users’ potential interests, as well as the measurement of their effectiveness.
For these purposes, so-called user profiles are created and stored in a file (known as a “cookie”) or similar methods are used to store user information relevant to the display of the aforementioned content. This may include, for example, content viewed, websites visited, online networks used, as well as communication partners and technical details such as the browser and computer system used, along with information on usage times and functions used. If users have consented to the collection of their location data, this data may also be processed.
In addition, users’ IP addresses are stored. However, we use available IP masking methods (i.e., pseudonymization by truncating the IP address) to protect users. In general, no plaintext user data (such as email addresses or names) is stored as part of the online marketing process; instead, pseudonyms are used. This means that neither we nor the providers of the online marketing services know the users’ actual identities, but only the information stored in their profiles.
Notes on Legal Bases: If we ask users for their consent to the use of third-party providers, the legal basis for data processing is that consent. Otherwise, user data is processed based on our legitimate interests (i.e., our interest in providing efficient, cost-effective, and user-friendly services). In this context, we would also like to draw your attention to the information regarding the use of cookies in this Privacy Policy.
Information on Revocation and Objection: Please refer to the privacy policies of the respective providers and the opt-out options provided by them. If no explicit opt-out option has been provided, you have the option of disabling cookies in your browser settings. However, this may limit certain features of our online service. We therefore also recommend the following opt-out options:
a) Europe: https://youronlinechoices.eu/.
b) Canada: https://youradchoices.ca/.
c) United States: https://optout.aboutads.info/.
d) Cross-regional: https://optout.aboutads.info.
- Types of Data Processed: Usage data (e.g., page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and features). Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, individuals involved).
- Affected individuals: Users (e.g., website visitors, users of online services).
- Purposes of processing and legitimate interests: Audience measurement (e.g., traffic statistics, identification of returning visitors); tracking (e.g., interest-based/behavior-based profiling, use of cookies); Target audience segmentation; marketing; profiles containing user-related information (creation of user profiles); conversion tracking (measuring the effectiveness of marketing measures).
- Safety Measures: IP masking (pseudonymization of the IP address).
- Legal Basis: Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR). Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
Additional information on processing procedures, methods, and services:
- Google Ads and Conversion Tracking: Online marketing methods used to place content and ads within the service provider’s advertising network (e.g., in search results, in videos, on websites, etc.) so that they are displayed to users who are presumed to be interested in the ads. In addition, we measure ad conversion—that is, whether users have interacted with the ads and taken advantage of the advertised offers (so-called conversions). However, we receive only anonymous information and no personal information about individual users; Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal Basis: Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR), Legitimate Interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR); Website: https://marketingplatform.google.com; Privacy Policy: https://business.safety.google/privacy/; Basis for Transfers to Third Countries: Data Privacy Framework (DPF).
- Google AdSense with personalized ads: We integrate the Google AdSense service, which allows us to place personalized ads within our website; Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal Basis: Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR); Privacy Policy: https://business.safety.google/privacy/; Basis for Transfers to Third Countries: Data Privacy Framework (DPF).
- Google AdSense with non-personalized ads: We use the Google AdSense service to display non-personalized ads on our website. These ads are not based on individual user behavior but are selected based on general characteristics such as the page content or your approximate geographic location; Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal Basis: Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR); Privacy Policy: https://business.safety.google/privacy/; Basis for Transfers to Third Countries: Data Privacy Framework (DPF).
Customer Reviews and Rating Processes
We participate in review and rating processes to evaluate, optimize, and promote our services. When users rate us or provide feedback through the participating review platforms or processes, the providers’ Terms and Conditions or Terms of Use and Privacy Policy also apply. As a rule, submitting a rating also requires registration with the respective providers.
To ensure that the reviewers have actually used our services, we transmit the necessary data regarding the customer and the service used to the respective review platform with the customer’s consent (including name, email address, and order number or item number). This data is used solely to verify the user’s authenticity.
- Types of Data Processed: Contract data (e.g., subject matter of the contract, term, customer category); usage data (e.g., page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and features). Meta, communication, and process data (e.g., IP addresses, timestamps, identification numbers, individuals involved).
- Affected individuals: Service recipients and clients. Users (e.g., website visitors, users of online services).
- Purposes of processing and legitimate interests: Feedback (e.g., collecting feedback via an online form). Marketing.
- Legal Basis: Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
Plug-ins, embedded features, and content
We incorporate functional and content elements into our online offering that are sourced from the servers of their respective providers (hereinafter referred to as “third-party providers”). These may include, for example, graphics, videos, or city maps (hereinafter collectively referred to as “content”).
This integration always requires that the third-party providers of this content process users’ IP addresses, since they would not be able to send the content to users’ browsers without an IP address. The IP address is therefore necessary for displaying this content or these features. We make every effort to use only content whose respective providers use the IP address solely for the purpose of delivering the content.
Notes on Legal Bases: If we ask users for their consent to the use of third-party providers, the legal basis for data processing is that consent. Otherwise, user data is processed based on our legitimate interests (i.e., our interest in providing efficient, cost-effective, and user-friendly services). In this context, we would also like to draw your attention to the information regarding the use of cookies in this Privacy Policy.
- Types of Data Processed: Usage data (e.g., page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and features); Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, individuals involved). Location data (information regarding the geographic position of a device or a person).
- Affected individuals: Users (e.g., website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online services and user-friendliness; audience measurement (e.g., traffic statistics, identification of returning visitors); tracking (e.g., interest-based/behavioral profiling, use of cookies); target audience segmentation. Marketing.
- Legal Basis: Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR). Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
Additional information on processing procedures, methods, and services:
- Google Fonts (hosted on your own server): Provision of font files to ensure a user-friendly display of our online content; Service Provider: Google Fonts are hosted on our server; no data is transmitted to Google; Legal Basis: Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR).
- Google Maps: We embed maps from the "Google Maps" service provided by Google. The data processed may include, in particular, users' IP addresses and location data; Service Provider: Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland; Legal Basis: Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR); Website: https://mapsplatform.google.com/; Privacy Policy: https://business.safety.google/privacy/. Basis for Transfers to Third Countries: Data Privacy Framework (DPF).
- YouTube videos: Video content; Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal Basis: Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR); Website: https://www.youtube.com; Privacy Policy: https://business.safety.google/privacy/; Basis for Transfers to Third Countries: Data Privacy Framework (DPF). Right to Opt Out: Opt-Out Plugin: https://tools.google.com/dlpage/gaoptout?hl=de, Settings for displaying ads: https://myadcenter.google.com/personalizationoff.
Changes and Updates
We ask that you review the content of our Privacy Policy on a regular basis. We will update the Privacy Policy as soon as changes to our data processing activities make this necessary. We will notify you as soon as the changes require action on your part (e.g., consent) or any other individual notification.
If we provide addresses and contact information for companies and organizations in this Privacy Policy, please note that these addresses may change over time, and we ask that you verify the information before contacting them.
Phases of Development & Future Expansions
Wozoria Sports OS is currently undergoing active development. The following planned feature enhancements may affect data processing. In the event of significant changes, users will be notified and, if necessary, asked to provide their consent again:
- Parent Portal: Planned direct access for parents and guardians to their children's sports data via separate user accounts with restricted permissions.
- Push Notifications: Opt-in-based notifications about practices, game schedules, and club news. Use requires express consent.
- Payment Module: Planned integration of a payment service provider for membership fees. Once activated, the payment provider’s supplementary privacy policy will apply.
- AI-powered training recommendations: Planned use of anonymized training data for personalized exercise recommendations — exclusively for internal club use; no disclosure to third parties.
- Cross-Club Tournaments: Data exchange between clubs (e.g., statistics on guest players) takes place only with the explicit consent of all affected clubs and users.
- Digital Parental Consent: Planned digital consent management for minors, with confirmation via email or app verification.
The most recent version of this Privacy Policy is available at www.wozoria.at/privacy-policy.html available.
Definitions of Terms
This section provides an overview of the terms used in this Privacy Policy. To the extent that these terms are defined by law, their legal definitions apply. The explanations below, however, are intended primarily to aid understanding.
- Affiliate Tracking: As part of affiliate tracking, links used by referring websites to direct users to websites offering products or other services are logged. The operators of the respective linking websites may receive a commission if users follow these so-called affiliate links and subsequently take advantage of the offers (e.g., purchase goods or use services). For this to happen, providers must be able to track whether users who are interested in specific offers subsequently take advantage of them as a result of the affiliate links. Therefore, for affiliate links to function properly, they must be supplemented with certain values that become part of the link or are stored elsewhere, such as in a cookie.
- Employees: The term “employee” refers to individuals who are in an employment relationship, whether as staff members, salaried employees, or in similar positions. An employment relationship is a legal relationship between an employer and an employee that is established by an employment contract or agreement.
- Inventory Data: Master data includes essential information required for the identification and management of contractual partners, user accounts, profiles, and similar assignments. This data may include, among other things, personal and demographic information such as names, contact information (addresses, phone numbers, email addresses), dates of birth, and specific identifiers (user IDs).
- Table of Contents: Content data includes information generated during the creation, editing, and publication of all types of content. This category of data may include text, images, videos, audio files, and other multimedia content published on various platforms and media.
- Contact Information: Contact information is essential data that enables communication with individuals or organizations. It includes, among other things, phone numbers, mailing addresses, and email addresses, as well as communication channels such as social media handles and instant messaging identifiers.
- Conversion Tracking: Conversion tracking (also known as "visit-to-action analysis") is a method used to determine the effectiveness of marketing campaigns. To do this, a cookie is typically stored on users' devices while they are on the websites where the marketing campaigns are running, and is then retrieved again on the target website.
- Meta, communication, and transaction data: Meta data, communication data, and procedural data are categories that contain information about how data is processed, transmitted, and managed. Metadata, also known as “data about data,” includes information that describes the context, origin, and structure of other data. It may include details such as file size, creation date, the author of a document, and revision histories.
- Member Information: Member data includes information relating to individuals who are part of an organization, club, online service, or other group. This data is used to manage memberships, facilitate communication, and provide services or benefits associated with membership.
- Usage data: Usage data refers to information that tracks how users interact with digital products, services, or platforms. This data encompasses a wide range of information that reveals how users interact with applications, which features they prefer, how long they stay on specific pages, and the paths they take as they navigate through an application.
- Personal Data: "Personal data" means any information relating to an identified or identifiable natural person (hereinafter referred to as the "data subject"); a natural person is considered identifiable if they can be identified, directly or indirectly, in particular by association with an identifier such as a name, an identification number, location data, an online identifier (e.g., a cookie) or one or more specific characteristics that reflect the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
- Profiles containing user-specific information: The processing of “profiles containing user-related information,” or “profiles” for short, encompasses any type of automated processing of personal data that involves using such personal data to analyze, evaluate, or predict certain personal aspects relating to a natural person (depending on the type of profiling, this may include various information regarding demographics, behavior, and interests, such as interaction with websites and their content, etc.) to analyze, evaluate, or predict them.
- Log data: Log data is information about events or activities that have been logged in a system or network. This data typically includes information such as timestamps, IP addresses, user actions, error messages, and other details about the use or operation of a system.
- Range Measurement: Audience measurement (also known as web analytics) is used to analyze visitor traffic to an online service and may include the behavior or interests of visitors regarding specific information, such as website content. With the help of reach analysis, operators of online services can, for example, determine at what times users visit their websites and what content they are interested in.
- Location Data: Location data is generated when a mobile device (or another device capable of determining its location) connects to a cellular cell, a Wi-Fi network, or similar technical means and location-determination functions.
- Tracking: "Tracking" refers to the ability to track users' behavior across multiple online services. Typically, information about users' behavior and interests in relation to the online services they use is stored in cookies or on the servers of the providers of tracking technologies (a process known as "profiling").
- Responsible Party: The term "controller" refers to the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: "Processing" means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and encompasses virtually any interaction with data, whether it involves collection, analysis, storage, transmission, or deletion.
- Contract Information: Contract data consists of specific information related to the formalization of an agreement between two or more parties. It documents the terms under which services or products are provided, exchanged, or sold.
- Payment Information: Payment data includes all information required to process payment transactions between buyers and sellers. This data is crucial for e-commerce, online banking, and any other form of financial transaction.
- Target Audience Identification: The term "Custom Audiences" refers to the process of defining target audiences for advertising purposes, such as displaying ads. For example, based on a user’s interest in certain products or topics online, it can be inferred that this user is interested in ads for similar products.
Created using the free Datenschutz-Generator.de tool by Dr. Thomas Schwenke