top of page

Privacy Policy – Tai Chi & Qi Gong Courses

 

We are pleased that you are interested in our website and our course offerings. Protecting your personal data is important to us. This Privacy Policy explains, in accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR), which personal data we process when you visit our website and in connection with our Tai Chi and Qi Gong courses, the purposes for which we process such data, and your rights.

This Privacy Policy applies to our website www.taichiroots.de and to all services offered through it, in particular the booking and delivery of Tai Chi and Qi Gong courses.

 

 

1. Data Controller

 

Tai Chi Roots
Owner / Course Instructor: Marian Żóraw

 

Postal Address:
c/o Zwei Kraniche GmbH
S-Bahnhof Hermsdorf
Nordtunnel
Bahnhofplatz 0
13467 Berlin
Germany

 

Email: info@taichiroots.de

 

 

2. Definitions

 

This Privacy Policy uses the terminology of the General Data Protection Regulation (GDPR).

 

Personal data means any information relating to an identified or identifiable natural person.

 

Processing means any operation or set of operations performed on personal data, such as collecting, recording, organising, storing, using, disclosing, transmitting or deleting data.

 

Data subject means any natural person whose personal data is processed.

 

 

3. Legal Bases for Processing

 

We process personal data only where permitted by law.

 

In particular, processing may be based on one of the following legal grounds:

  • Article 6(1)(a) GDPR – Consent

  • Article 6(1)(b) GDPR – Performance of a contract or pre-contractual measures

  • Article 6(1)(c) GDPR – Compliance with a legal obligation

  • Article 6(1)(f) GDPR – Legitimate interests

 

Special categories of personal data (in particular health data) are processed only on the basis of your explicit consent pursuant to Article 9(2)(a) GDPR.

 

 

4. Website Hosting

 

Our website is hosted by Wix.com Ltd.

 

Wix provides, among other things:

  • Web hosting

  • Content Management System (CMS)

  • Contact forms

  • Booking system

  • Technical infrastructure

  • Security features

  • Cookie management

 

When you visit our website, the following technical information is automatically processed, including:

  • IP address

  • Date and time of access

  • Browser type and version

  • Operating system

  • Language settings

  • Referrer URL

  • Pages visited

  • Device information

  • Server log files

  •  

This data is required to provide the website technically, detect attacks on our systems, correct errors, and ensure the stability and security of the website.

 

The legal basis for this processing is Article 6(1)(f) GDPR (legitimate interests).

 

As part of Wix's services, personal data may be processed in countries outside the European Union (EU) or the European Economic Area (EEA). Where personal data is transferred to third countries, such transfers take place only on the basis of appropriate safeguards in accordance with Articles 44 et seq. GDPR, in particular by means of Standard Contractual Clauses or an adequacy decision of the European Commission, where applicable.

 

 

5. SSL/TLS Encryption

 

To protect your data, this website uses SSL/TLS encryption.

 

You can recognise an encrypted connection by the presence of "https://" in your browser's address bar and the padlock symbol.

 

Encryption helps prevent data transmitted between your browser and our website from being intercepted or altered by unauthorised third parties.

 

 

6. Server Log Files

 

When you visit our website, our hosting provider automatically collects and stores information in so-called server log files.

 

This information includes, in particular:

  • IP address

  • Browser type

  • Browser version

  • Operating system

  • Date and time of access

  • Pages accessed

  • Amount of data transferred

  • Referrer URL

  • Reports of successful or failed access attempts

 

This data is used exclusively to ensure the technical security of the website, analyse errors, and guarantee its reliable operation.

 

As a general rule, this data is not combined with data from other sources.

 

The legal basis for this processing is Article 6(1)(f) GDPR (legitimate interests).

 

 

7. Cookies and Consent Management

 

Our website uses cookies and similar technologies. Cookies are small text files that are stored on your device.

 

We distinguish in particular between:

  • Technically necessary cookies

  • Functional cookies

  • Analytics cookies

  • Marketing cookies

 

Technically necessary cookies are required to ensure the secure operation of the website and to provide certain functions, such as the booking system or saving your cookie preferences.

 

Analytics and marketing cookies are used only if you have given your explicit consent.

 

Your consent is managed via the cookie banner displayed on our website.

 

You may withdraw your consent or change your cookie settings at any time with effect for the future.

 

Legal bases:

  • Article 6(1)(a) GDPR (Consent)

  • Article 6(1)(f) GDPR (Technically necessary cookies)

  • Section 25 German Telecommunications Digital Services Data Protection Act (TDDDG) (Storage of information on end-user devices and access to such information)

 

 

8. Contacting Us

 

If you contact us by email or via the contact form on our website, we process the personal data you provide solely for the purpose of responding to your enquiry.

 

This may include, in particular:

  • Name

  • Email address

  • Telephone number

  • The content of your message

 

Your data is processed solely for communication with you and for handling your request.

 

Legal bases:

  • Article 6(1)(b) GDPR (Pre-contractual measures)

  • Article 6(1)(f) GDPR (Legitimate interest in responding efficiently to enquiries)

 

Your data will be deleted once your enquiry has been fully dealt with, provided that no statutory retention obligations or other legitimate reasons require us to retain it.

 

 

9. Booking Courses via Wix Bookings

 

Registration for our Tai Chi and Qi Gong courses is carried out through Wix Bookings, which forms part of the Wix platform.

 

When you make a booking, we process, in particular, the following personal data:

  • First and last name

  • Postal address

  • Telephone number

  • Email address

  • Date of birth (where required)

  • Booked course and course dates

  • Booking and attendance history

  • Payment status

  • Voluntary information provided during the booking process

 

This data is processed for the purpose of organising, administering and delivering our courses, as well as fulfilling the contract concluded between you and us.

 

Legal bases:

  • Article 6(1)(b) GDPR (Performance of a contract)

  • Article 6(1)(c) GDPR (Compliance with statutory retention obligations)

 

 

10. Delivery of Our Courses

 

To properly organise and deliver our courses, we process the personal data necessary for this purpose.

 

This includes, in particular:

  • Managing participant lists

  • Course administration

  • Communication before and after the course

  • Notifications of schedule changes

  • Waiting list management

  • Recording attendance

  • Issuing invoices

  • Compliance with tax and accounting obligations

 

Personal data is processed only to the extent necessary for these purposes.

 

Legal bases:

  • Article 6(1)(b) GDPR

  • Article 6(1)(c) GDPR

  • Article 6(1)(f) GDPR

 

 

11. Processing of Voluntarily Provided Health Data

 

Tai Chi and Qi Gong are health-oriented forms of exercise. To ensure that classes can be conducted as safely as possible and adapted to individual needs, you may voluntarily provide us with health-related information.

 

This may include, in particular:

  • Existing medical conditions

  • Injuries

  • Musculoskeletal complaints

  • Pregnancy

  • Previous operations

  • Balance or circulatory problems

  • Chronic illnesses

  • Any other health information relevant to your participation

 

Providing this information is entirely voluntary.

Participation in our courses is generally possible without providing health information, unless there are health-related reasons that make such information necessary.

 

Health data is processed solely for the purpose of:

  • Conducting classes safely

  • Adapting exercises where appropriate to individual needs

  • Minimising health risks as far as possible

 

Health data is accessible only to the course instructor or teaching staff and is treated with the strictest confidentiality.

 

As a general rule, this information is not shared with third parties.

 

The only exception is in the event of a medical emergency, where disclosure of specific information may be necessary to protect your vital interests.

 

Legal basis:

  • Article 9(2)(a) GDPR (Explicit consent)

 

You may withdraw your consent at any time with effect for the future.

 

Withdrawal of consent does not affect the lawfulness of any processing carried out before the withdrawal.

 

 

12. Emergency Contact

 

You may voluntarily provide the details of an emergency contact.

 

The following data may be processed:

  • Name

  • Telephone number

  • Relationship to the participant

 

This information will be used only if a medical emergency occurs during a course and it is necessary to contact the person concerned.

 

Legal bases:

  • Article 6(1)(d) GDPR (Protection of vital interests)

  • Article 6(1)(a) GDPR (Voluntary provision of information)

 

Where you voluntarily provide the personal data of an emergency contact, this data is not collected directly from that individual but is supplied by you as the participant.

 

You are responsible for informing your emergency contact that you have shared their personal data with Tai Chi Roots – Marian Żóraw and that their data will be processed in accordance with this Privacy Policy.

 

The emergency contact's information will be used solely if a medical or other urgent situation arises during a course and it becomes necessary to contact them.

 

The information will be treated confidentially and deleted once it is no longer required for the administration of our courses.

 

 

13. Payment Processing

 

Depending on the services offered, we provide various payment methods for our courses.

 

These include, in particular:

  • Wix Payments

  • PayPal

 

For the purpose of processing payments, we process only the personal data necessary to complete the transaction.

 

Depending on the payment method, this may include:

  • Name

  • Billing address

  • Email address

  • Payment amount

  • Booking reference

  • Payment status

  • Payment references

 

Where external payment service providers are used, their respective privacy policies also apply.

 

As a general rule, we do not receive your complete bank account or credit card details.

 

Legal basis:

  • Article 6(1)(b) GDPR (Performance of a contract)

 

 

14. Invoicing and Statutory Record Retention

 

To comply with commercial and tax law obligations, we issue invoices for booked services.

 

For this purpose, we process, in particular:

  • Name

  • Postal address

  • Invoice details

  • Description of the services provided

  • Payment information

 

Invoices and related accounting records are retained in accordance with the statutory retention periods.

 

Once the applicable legal retention periods have expired, the data will be deleted unless there are other legal grounds requiring continued retention.

 

Legal bases:

  • Article 6(1)(c) GDPR (Compliance with a legal obligation)

  • Article 6(1)(b) GDPR (Performance of a contract)

 

 

15. Communication by Telephone and Email

 

You may contact us by telephone or email.

 

In doing so, we process the personal data you provide solely for the purpose of handling your enquiry.

 

This may include:

  • Name

  • Telephone number

  • Email address

  • The content of your message

  • Date and time of your enquiry

 

Your personal data is processed solely for the purpose of taking pre-contractual steps, performing a contract, or responding to your enquiry.

 

Legal bases:

  • Article 6(1)(b) GDPR

  • Article 6(1)(f) GDPR

 

 

16. Photographs and Video Recordings

 

As a general rule, no photographs or video recordings are taken during our courses.

 

Should photographs or recordings be made in individual cases—for example, for use on our website, in informational materials, or on future social media channels—this will take place only with your prior, voluntary, and explicit consent.

 

The following types of recordings may be made:

  • Group photographs

  • Individual photographs

  • Short video recordings of practice sessions

 

Before any publication, the individuals concerned will be informed of the intended purpose of use.

 

Your consent is voluntary and may be withdrawn at any time with effect for the future.

Withdrawal of consent does not affect the lawfulness of any processing carried out before the withdrawal. Published content will be removed wherever technically and legally possible. However, complete deletion of content that has already been shared further or archived by third parties cannot be guaranteed in every case.

 

Legal basis:

  • Article 6(1)(a) GDPR (Consent)

 

 

17. Data Retention

 

We retain personal data only for as long as necessary to fulfil the respective processing purposes.

 

In particular, the following principles apply:

  • Contract-related data is retained in accordance with the statutory retention periods.

  • Invoices and accounting records are retained in accordance with applicable commercial and tax legislation.

  • Health data is retained only for as long as necessary to ensure the safe delivery of our courses.

 

Where participants do not attend any further courses and there are no statutory retention obligations, voluntarily provided health data will be deleted.

 

Once the relevant processing purpose no longer applies and any statutory retention periods have expired, personal data will either be deleted or anonymised in accordance with applicable data protection requirements.

 

 

18. Web Analytics with Google Analytics 4

 

Provided that you have given your consent via our cookie banner, we use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

 

Google Analytics enables us to analyse the use of our website in an anonymised manner so that we can improve both its technical performance and content.

 

In particular, the following information may be processed:

  • Truncated IP address

  • Information about your device

  • Browser type and version

  • Operating system

  • Language settings

  • Pages visited

  • Time spent on pages

  • Click behaviour

  • Referrer URL

  • Approximate location data

  • Date and time of your visit

 

Google Analytics 4 uses cookies and similar technologies to recognise returning devices.

 

IP anonymisation is enabled by default. Nevertheless, it cannot be entirely ruled out that data may be transmitted to Google's servers, including servers located outside the European Union (EU) or the European Economic Area (EEA).

 

Processing takes place solely on the basis of your voluntary consent.

 

Legal basis:

  • Article 6(1)(a) GDPR

  • Section 25 TDDDG

 

You may withdraw your consent at any time with effect for the future by changing your cookie preferences.

 

 

19. Google Search Console

 

We use Google Search Console to optimise our website from a technical perspective.

 

This service provides us with statistical information about our website's visibility in search engines, such as search queries, click rates, and indexing errors.

 

To the best of our knowledge, Google Search Console does not process personal data that can be directly attributed to individual visitors to our website.

 

Should personal data nevertheless be processed, such processing is based on our legitimate interest in maintaining a technically reliable and easily discoverable website.

 

Legal basis:

  • Article 6(1)(f) GDPR (Legitimate interests)

 

 

20. Integration of Google Maps

 

Our website may include the Google Maps service provided by Google Ireland Limited.

 

The maps help you locate the venue where our courses take place.

 

When you access an embedded map, personal data—particularly your IP address and technical information about your device—may be transmitted to Google.

 

For this reason, Google Maps is loaded only after you have given your explicit consent through our cookie banner.

 

Legal bases:

  • Article 6(1)(a) GDPR (Consent)

  • Section 25 TDDDG

 

 

21. Recipients of Personal Data

 

We disclose your personal data only where this is legally permitted or necessary for the performance of our contract with you.

 

Recipients may include, in particular:

  • Wix.com Ltd. (website hosting, website platform, and booking system)

  • Payment service providers (e.g. PayPal or Wix Payments)

  • Tax advisers or accounting service providers

  • Tax authorities where required by law

  • IT service providers performing maintenance or support services

  • Medical professionals or emergency services in the event of an emergency

 

Your personal data is not shared for marketing purposes.

 

 

22. Transfers of Personal Data to Third Countries

 

Some of the service providers we use may process personal data outside the European Union (EU) or the European Economic Area (EEA).

 

This applies in particular to:

  • Wix

  • Google

  • PayPal

 

Where personal data is transferred to so-called third countries, such transfers are carried out only in accordance with Articles 44 et seq. GDPR.

 

Appropriate safeguards may include, in particular:

  • Standard Contractual Clauses approved by the European Commission;

  • Adequacy decisions adopted by the European Commission (for example, under the EU–US Data Privacy Framework, where the relevant provider is certified); and

  • Other safeguards recognised under applicable data protection law.

 

 

23. Data Processing Agreements

 

Where we engage external service providers to process personal data on our behalf, this is done only on the basis of a Data Processing Agreement in accordance with Article 28 GDPR, or another lawful basis under applicable data protection legislation.

 

Our service providers are carefully selected and are contractually required to process personal data only in accordance with our instructions and in compliance with the applicable data protection laws.

 

 

24. Data Security

 

We implement appropriate technical and organisational measures in accordance with Article 32 GDPR to protect your personal data against loss, manipulation, unauthorised access, unauthorised disclosure, or any other unlawful processing.

 

These measures include, in particular:

  • Encrypted data transmission (SSL/TLS)

  • Access control and authorisation procedures

  • Password protection

  • Regular updates of the software we use

  • Data backups

  • Careful selection of our technical service providers

 

Despite all security measures, complete security of data transmission over the internet cannot be guaranteed.

 

 

25. Your Rights as a Data Subject

 

As a data subject under the General Data Protection Regulation (GDPR), you have the following rights:

 

a) Right of Access (Article 15 GDPR)

 

You have the right to obtain confirmation as to whether we process personal data relating to you.

 

Where this is the case, you are entitled, in particular, to information about:

 

* the personal data being processed;

* the purposes of the processing;

* the categories of personal data concerned;

* the recipients or categories of recipients to whom the data has been or will be disclosed;

* the planned retention period;

* the source of the data, where it was not collected directly from you; and

* the existence of your rights under the GDPR.

 

b) Right to Rectification (Article 16 GDPR)

 

You have the right to request the prompt correction of inaccurate personal data concerning you.

 

You also have the right to have incomplete personal data completed.

 

c) Right to Erasure ("Right to be Forgotten") (Article 17 GDPR)

 

You may request the deletion of your personal data where the legal requirements are met.

 

This applies in particular where:

 

* the data is no longer necessary for the purpose for which it was originally collected;

* you have withdrawn your consent;

* you have successfully objected to the processing;

* the processing is unlawful; or

* there is a legal obligation to erase the data.

 

The right to erasure does not apply where statutory retention obligations or other legal exemptions prevent deletion.

 

d) Right to Restriction of Processing (Article 18 GDPR)

 

Under the conditions laid down by law, you have the right to request that the processing of your personal data be restricted.

 

e) Right to Data Portability (Article 20 GDPR)

 

You have the right to receive the personal data that you have provided to us, where we process it by automated means on the basis of your consent or for the performance of a contract, in a structured, commonly used and machine-readable format.

 

Where technically feasible, you also have the right to request that this data be transmitted directly to another controller.

 

f) Right to Object (Article 21 GDPR)

 

Where we process your personal data on the basis of our legitimate interests (Article 6(1)(f) GDPR), you have the right to object to such processing at any time on grounds relating to your particular situation.

 

Where personal data is processed for the purposes of direct marketing, you have the right to object to such processing at any time without giving reasons.

 

g) Right to Withdraw Consent (Article 7(3) GDPR)

 

You may withdraw any consent you have given at any time with effect for the future.

 

Withdrawal of consent does not affect the lawfulness of any processing carried out before the withdrawal.

 

 

26. Right to Lodge a Complaint with a Supervisory Authority

 

If you believe that the processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with a data protection supervisory authority.

 

In particular, you may contact the supervisory authority responsible for your habitual residence, your place of work, or the place where the alleged infringement occurred.

 

 

27. Obligation to Provide Personal Data

 

The provision of personal data may be required by law, by contract, or may be necessary for the conclusion and performance of a contract.

 

In particular, we require certain personal details and contact information in order to register you for and administer our courses.

 

The provision of health data is entirely voluntary. If you choose to provide such information, we will use it only where necessary to ensure the safe delivery of our courses.

 

If the personal data required for the conclusion or performance of a contract is not provided, it may not be possible to establish or carry out the contractual relationship.

 

 

28. Automated Decision-Making and Profiling

 

We do not carry out automated decision-making within the meaning of **Article 22 GDPR**.

 

We also do not carry out profiling.

 

 

29. Links to External Websites

 

Our website may contain links to third-party websites.

 

The operators of those websites are solely responsible for their content and privacy practices.

 

We recommend that you review the privacy policies of the respective providers before submitting any personal data to those websites.

 

 

30. Confidentiality

 

We treat all personal data as confidential.

 

Health data and other particularly sensitive personal data are processed only to the extent necessary and are accessible only to those persons who require the information for the administration and delivery of our courses.

 

We also ensure that any service providers engaged by us comply with the applicable data protection requirements.

 

 

31. Changes to this Privacy Policy

 

We reserve the right to amend this Privacy Policy where necessary due to changes in the law, new technical developments, or changes to our services.

 

The version published on our website at the time of your visit shall apply.

 

Where changes require your consent or have a significant impact on the processing of personal data, we will inform you in accordance with the applicable legal requirements.

 

 

32. Contact Regarding Data Protection

 

If you have any questions regarding data protection or the processing of your personal data, you may contact us at any time.

 

Data Controller within the meaning of the General Data Protection Regulation (GDPR):

 

Marian Żóraw

Owner / Course Instructor

 

Postal Address:

c/o Zwei Kraniche GmbH

S-Bahnhof Hermsdorf

Nordtunnel

Bahnhofplatz 0

13467 Berlin

Germany

 

Email: info@taichiroots.de

bottom of page