Privacy Policy
This Privacy Policy explains how personal data is processed and protected when you visit this website, contact us, or use services provided by HOLYSTIC YOU.

HOLYSTIC YOU
Tara Gupta, Sole Proprietor
Menzinger Straße 1,
80638 Munich
Germany

Email: info@holysticyou.de
Phone: +49 89 97861997
1. Data Controller
The controller responsible for the processing of personal data on this website within the meaning of Article 4(7) of the General Data Protection Regulation (GDPR) is:
Tara Gupta
HOLYSTIC YOU
Menzinger Straße 1
80638 Munich
Germany
Email: info@holysticyou.de
Phone: +49 89 97861997

2. Processing of Personal Data

2.1 Data you voluntarily provide
When you use the contact form, submit booking enquiry, or contact us by email or telephone, the following personal data may be processed in particular:

– Name
– Email address
– Telephone number
– Content and subject matter of your enquiry
– Information relating to requested appointments or services
– Address, billing, and payment information, where required for contractual processing
– Health data, where you provide such data in connection with a treatment enquiry or treatment and its processing is necessary

General contact, booking, and contractual data is processed for the purpose of responding to your enquiry and taking steps prior to entering into or performing a contract. The legal basis is Article 6(1)(b) GDPR.
Where processing is necessary to comply with statutory obligations, particularly tax or commercial record-keeping obligations, the legal basis is Article 6(1)(c) GDPR.
Health data is processed only where necessary for medical diagnosis, healthcare, or treatment in connection with the provision of Heilpraktiker services.
The legal basis is Article 9(2)(h) GDPR in conjunction with Section 22(1)(1)(b) of the German Federal Data Protection Act (BDSG).
Where possible, please do not submit detailed medical records or particularly sensitive health information through the general contact form.

2.2 Data processed automatically when you visit the website
This website is hosted through Webflow. When you access the website, Webflow processes technical connection and server log data required for its operation. This may include in particular:

– IP address
– Date and time of access
– Page or file requested
– Previously visited website or referrer URL
– Browser type and version
– Operating system and device type
– Amount of data transferred and access status

This data is processed to provide the website and ensure its stability and security. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure, stable, and functional provision of this website.
Webflow, Inc., 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA, processes this data as a technical service provider. Further information concerning data processing and possible transfers of data to the United States is provided in the “Hosting and External Service Providers” section of this Privacy Policy.

2.3 Cookies and Analytics
This website uses only cookies or similar storage technologies that are technically necessary for the proper and secure provision of the website.
Technically necessary cookies and storage technologies are used in accordance with Section 25(2)(2) TDDDG. Where personal data is processed, the legal basis is Article 6(1)(f) GDPR.
We currently do not use any additional analytics or marketing services such as Google Analytics or Meta Pixel and do not place any corresponding tracking cookies.
3. Purposes of Processing
We process personal data only for specified and lawful purposes. These purposes include in particular:
– responding to contact and appointment enquiries
– entering into, performing, and administering treatment, yoga, coaching, and other service agreements
– providing Heilpraktiker and health-related services
– arranging and managing appointments
– issuing invoices and complying with tax and commercial record-keeping obligations
– communicating with patients, clients, customers, and prospective clients
– ensuring the secure, stable, and functional operation of this website
– preventing misuse and establishing, exercising, or defending legal claims
– providing optional functions or analytics where you have given your consent
4. Legal Bases for Processing
Depending on the purpose and nature of the processing, we rely on the following legal bases:

Steps prior to entering into a contract and performance of a contract
Contact, booking, billing, and contractual data is processed on the basis of Article 6(1)(b) GDPR where this is necessary to respond to a contract-related enquiry, take steps prior to entering into a contract, or perform a contract.

Health data and treatment services
Where health data is necessary for medical diagnosis, healthcare, or treatment in connection with the provision of Heilpraktiker services, it is processed on the basis of Article 9(2)(h) GDPR in conjunction with Section 22(1)(1)(b) of the German Federal Data Protection Act (BDSG).

Legal obligations
Where we are legally required to process or retain personal data, particularly under tax or commercial law, the processing is based on Article 6(1)(c) GDPR.

Legitimate interests
Personal data may be processed on the basis of Article 6(1)(f) GDPR where this is necessary to protect our legitimate interests or those of a third party and those interests are not overridden by the interests or fundamental rights of the data subject. This applies in particular to:
– ensuring the secure and reliable operation of this website
– responding to general enquiries that are not directly related to a contract
– preventing misuse and fraud
– establishing, exercising, or defending legal claimsWhere health data must be processed in connection with legal claims, the additional legal basis is Article 9(2)(f) GDPR.

Consent
Where you have expressly consented to a specific form of processing, the legal basis is Article 6(1)(a) GDPR. Where express consent relates to the processing of health data, Article 9(2)(a) GDPR also applies.

You may withdraw your consent at any time with effect for the future. The withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Where optional analytics functions store or access information on your device, Section 25(1) TDDDG also applies.
5. Disclosure of Personal Data
Personal data is disclosed only where this is necessary to provide our services, required by law, based on your consent, or otherwise permitted by an applicable legal basis.

Depending on the service used, recipients or categories of recipients may include:
– Webflow, Inc., as the provider of the website and hosting platform
– email, telecommunications, and other IT service providers
– appointment booking and administration service providers, where such services are used
– payment service providers, where electronic payment processing is used
– tax advisers, accounting service providers, tax authorities, and other competent authorities where required by law
– medical or diagnostic laboratories where necessary to carry out a test or health service commissioned by you
– legal advisers, courts, public authorities, and professional liability insurers where necessary to establish, exercise, or defend legal claims

Processors engaged by us process personal data only in accordance with our instructions and on the basis of a data processing agreement pursuant to Article 28 GDPR.

Any other disclosure will take place only with your consent or where we are legally required or permitted to disclose the data.

We do not sell personal data or disclose it to third parties for their own advertising purposes.
6. Storage Periods
We retain personal data only for as long as necessary for the respective processing purpose or for as long as statutory retention obligations apply. The data is subsequently deleted or anonymised unless another legal basis permits or requires continued storage.

The following principles apply in particular:

Contact enquiries
Data relating to general contact enquiries is deleted once the enquiry has been fully dealt with, unless the enquiry results in a contractual or treatment relationship or statutory retention obligations or legitimate interests require continued storage.

Contractual and service data
Contract-related data is retained for the duration of the contractual relationship and generally until the applicable statutory limitation periods have expired. The regular limitation period under German law is three years and generally begins at the end of the year in which the respective claim arose.

Treatment records
Treatment records and the health data contained in them are generally retained for ten years following completion of the treatment in accordance with Section 630f(3) of the German Civil Code (BGB). Longer retention periods may apply where required by law or justified by particular medical or legal circumstances.

Tax and business records
The applicable retention period depends on the type of document. In particular, the following periods generally apply:
– ten years for accounting books, records, annual financial statements, and certain other tax-related documents
– eight years for accounting vouchers and invoice records
– six years for received and sent commercial or business correspondence and certain other tax-related documents

The respective period generally begins at the end of the calendar year in which the document was created or the last entry was made.

Consent-based processing
Data processed on the basis of consent is generally retained until consent is withdrawn or the relevant processing purpose no longer applies. Statutory retention and documentation obligations remain unaffected.

Technical website and analytics data
Technical log and security data is deleted or anonymised once it is no longer required for the operation and security of the website. Data processed by Webflow or any analytics service used is also subject to the retention periods specified in the applicable contractual terms or privacy information.
7. Your Data Protection Rights
Subject to the applicable legal requirements, you have the following rights in particular:
- Right of access pursuant to Art. 15 GDPR
- Right to rectification pursuant to Art. 16 GDPR
- Right to erasure pursuant to Art. 17 GDPR
- Right to restriction of processing pursuant to Art. 18 GDPR
- Right to data portability pursuant to Art. 20 GDPR
- Right to object to processing pursuant to Art. 21 GDPR
- Right to withdraw consent pursuant to Art. 7(3) GDPR

The withdrawal of consent takes effect for the future. It does not affect the lawfulness of processing carried out before the withdrawal.

You also have the right to lodge a complaint with a data protection supervisory authority pursuant to Art. 77 GDPR.

The supervisory authority responsible for HOLYSTIC YOU is:
Bavarian State Office for Data Protection Supervision (BayLDA)  
Promenade 18  
91522 Ansbach  
Germany  
www.lda.bayern.de

To exercise your rights, please contact:
Email: info@holysticyou.de
8. Data Security
HOLYSTIC YOU implements appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration and disclosure. These measures include access restrictions, the careful selection of service providers and, where technically supported, encrypted transmission using TLS.

The website is provided through Webflow.
Despite appropriate security measures, completely risk-free transmission of data over the internet cannot be guaranteed.
9. External Links
This website may contain links to websites or platforms operated by third parties. When you click such a link, you leave the HOLYSTIC YOU website. The external provider may then process information including your IP address, technical connection data and, where applicable, the referring page.

The respective external provider is generally responsible for the processing of personal data on its website. The provider’s own privacy notice applies.

Where external content or functions are embedded directly into this website, data may be transmitted when the relevant page is opened. Where legally required, such content will only be activated after you have given your consent.
10. Hosting, Buchungs- und Kommunikationsdienste
10.1 Webflow
This website is created and hosted using Webflow. The provider is:

Webflow, Inc.  398 11th Street, 2nd Floor  San Francisco, CA 94103  USA

When you access the website, Webflow may process IP addresses, browser and device information, technical log data and the date and time of the page request. Where forms are used on the website, Webflow may also process the information entered into those forms.

The processing is necessary for the secure and reliable provision of the website and is based on Art. 6(1)(f) GDPR. Where an inquiry relates to a contract or pre-contractual measures, processing is additionally based on Art. 6(1)(b) GDPR.

HOLYSTIC YOU has entered into a data processing agreement with Webflow. Personal data may be transferred to the United States. Webflow is certified under the EU-U.S. Data Privacy Framework. In addition, Webflow’s agreement provides for the use of the EU Standard Contractual Clauses.
Further information: https://webflow.com/legal/privacy

10.2 SimplyBook.me
SimplyBook.me may be used for booking Heilpraktiker and osteopathy appointments. The provider is:

SimplyBook.me Ltd.  Nafpliou 28, Medical Court, 4th Floor, Office 401  3025 Limassol  Cyprus

The data processed may include your name, contact details, selected service, appointment details and any information you voluntarily provide. Processing is necessary for arranging the appointment and performing the relevant contractual relationship pursuant to Art. 6(1)(b) GDPR.

Where health data is required in connection with an appointment, it is processed for the provision of health care pursuant to Art. 9(2)(h) GDPR. Please only provide information that is strictly necessary for arranging your appointment in freely accessible form fields.

SimplyBook.me is used as a data processor.
Further information: https://simplybook.me/en/policy

10.3 Zoom
Zoom may be used for online coaching sessions. The provider is:

Zoom Communications, Inc.  55 Almaden Boulevard, Suite 600  San Jose, CA 95113  USA

When Zoom is used, the data processed may include your name or display name, email address, device and connection data, session metadata and the audio and video data transmitted during the session.
Processing is necessary for conducting the agreed online session pursuant to Art. 6(1)(b) GDPR. Sessions are not recorded unless you have been expressly informed of the intended recording in advance and, where required, have given your consent.

Personal data may be transferred to the United States. Zoom is certified under the EU-U.S. Data Privacy Framework. The EU Standard Contractual Clauses may also apply.

Further information: https://www.zoom.com/en/trust/privacy/privacy-statement/

10.4 Eversports
Bookings for yoga classes may be made through Eversports. The provider is:

Eversports GmbH  Jakov-Lind-Straße 13 / Door 6 / 5th Floor  1020 Vienna  Austria

In connection with a booking, HOLYSTIC YOU may receive your name, contact details, booking and attendance information and details of the selected event. Processing is necessary for administering the booking and providing the booked class pursuant to Art. 6(1)(b) GDPR.

Eversports generally processes personal data collected through its own platform under its own responsibility as a data controller.
Further information: https://www.eversports.de/h/privacy

10.5 Urban Sports Club
If you book or check in for a class through Urban Sports Club, information including your name, membership or booking identifier, the selected class and your check-in may be transmitted to HOLYSTIC YOU.The platform is operated by:

Urban Sports GmbH  Novalisstraße 10  10115 Berlin  Germany

Processing is necessary to verify your eligibility to participate and to provide the booked class pursuant to Art. 6(1)(b) GDPR and, where applicable, for legitimate operational interests pursuant to Art. 6(1)(f) GDPR.

Where HOLYSTIC YOU and Urban Sports Club jointly determine the purposes and means of a particular processing operation, the parties act as joint controllers pursuant to Art. 26 GDPR. In other cases, Urban Sports Club processes platform user data under its own responsibility.

Further information: https://cms.urbansportsclub.com/en-de/urban-sports-club-privacy-policy

10.6 Wellhub
If you book or check in for a class through Wellhub, information including your name, membership or booking identifier, details of the selected class and your check-in may be transmitted to HOLYSTIC YOU.

According to Wellhub, the controller responsible for users in the European Economic Area is:

Gympass US LLC, doing business as Wellhub  30 Irving Place, 8th Floor  New York, NY 10003  USA

Processing by HOLYSTIC YOU is necessary to verify your eligibility to participate and to provide the booked class pursuant to Art. 6(1)(b) GDPR and, where applicable, for legitimate operational interests pursuant to Art. 6(1)(f) GDPR.

Wellhub generally processes data collected through its own platform under its own responsibility. Personal data may be transferred outside the European Economic Area. Wellhub states that it relies on approved transfer mechanisms, including the EU Standard Contractual Clauses.

Further information: https://wellhub.com/en-us/privacy/

10.7 Email Communication
If you contact HOLYSTIC YOU by email, your email address, the content of your message and any other information you provide will be processed.

Where your message relates to a contract or pre-contractual measures, processing is based on Art. 6(1)(b) GDPR. General inquiries are processed on the basis of the legitimate interest in responding appropriately to communications pursuant to Art. 6(1)(f) GDPR.

Please do not send detailed health information or medical documents by unencrypted email unless this has been expressly arranged in advance.

10.8 WhatsApp Communication
You may contact HOLYSTIC YOU through WhatsApp Business. The provider responsible for users in the European Economic Area is:

WhatsApp Ireland Limited
Merrion Road
Dublin 4, D04 X2K5
Ireland

When you contact us, the data processed may include your telephone number, profile information made available by you, the content of your messages and technical communication data.

Processing is necessary to respond to your inquiry pursuant to Art. 6(1)(b) GDPR or, in the case of general inquiries, is based on our legitimate interest in providing a convenient means of communication pursuant to Art. 6(1)(f) GDPR. Health data provided voluntarily will, where necessary, be processed pursuant to Art. 9(2)(h) GDPR.

WhatsApp messages are generally protected by end-to-end encryption. WhatsApp may process data outside the European Economic Area and states that it uses safeguards including the EU Standard Contractual Clauses.

Please do not send detailed medical documents or particularly sensitive health information through WhatsApp.

A connection to WhatsApp is only established when you click the WhatsApp link or contact HOLYSTIC YOU through WhatsApp.

Further information: https://www.whatsapp.com/legal/privacy-policy-eea
11. Updates to this Privacy Policy
This Privacy Policy will be updated where necessary to reflect legal, technical or organisational changes or the use of new services.

The current version will be published on this website.
Where required, material changes will be communicated in an appropriate manner.

Last updated: August 12, 2026