Privacy Policy Poland
1. Definitions
- Controller
- XF PILATES SP. Z O.O., al. Jana Pawła II 29, 33-100 Tarnów, Poland, KRS (National Court Register) No.: 0001254837, NIP (Tax Identification No.): 8733309602, REGON (Statistical No.): 545279247.
- Personal data
- any information relating to an identified or identifiable natural person, identifiable by reference to one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity, including the device IP address, location data, an online identifier and information collected by means of cookies and other similar technology.
- GDPR
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
- Website
- the website operated by the Controller at the address: https://strongpilates.pl
- User
- any natural person visiting the Website or using one or more of the services or functionalities described in this Privacy Policy.
- Consent of the data subject
- means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
- Profiling
- means the automated analysis of the User’s personal data by means of which, through the internet browser used by the User, the Controller may display personalised advertising or automatically select the offers and content best matched to the User’s needs or interests.
- Direct marketing
- activities consisting in addressing direct communications to customers, often in individual contact, serving to present and deliver advertising offers, commercial information and other informational, promotional and marketing materials.
2. Data controller
- The controller of your personal data is XF PILATES SP. Z O.O. with its registered office in Tarnów, al. Jana Pawła II 29, 33-100 Tarnów, Poland, entered in the register of entrepreneurs of the National Court Register under KRS No.: 0001254837, NIP: 8733309602, REGON: 545279247 (hereinafter: the “Controller”).
- The Controller may be contacted in writing at the address of the Controller’s registered office.
- In matters concerning personal data you may contact us at the e-mail address: iod@strongpilates.pl. If the Controller has appointed a Data Protection Officer, the address indicated is also the contact address of that Officer.
3. Purpose of processing and legal basis for the processing of data
Personal data will be processed:
- on the basis of Article 6(1)(a) GDPR, where you have given your consent to the processing of data:
- for the purpose of sending commercial information by means of electronic communication to the e-mail address indicated, including information concerning studio openings, the offer and promotions,
- for the purpose of carrying out analytical and statistical activities consisting in preparing analyses of User activity, improving the functionalities used and enhancing the operation of the Website,
- for the purpose of using Users’ personal data collected by means of cookies, including for marketing and profiling purposes,
- for the purpose of providing the Newsletter service;
- on the basis of Article 6(1)(b) GDPR, where this is necessary in order to take steps at the request of the data subject prior to entering into a contract or in order to perform a contract:
- for the purpose of handling the matter described by you in the electronic contact form or sign-up form available on the Website – in this case the processing of data by the Controller is necessary in order to conclude and perform a contract for the provision of services by electronic means
- for the purpose of arranging a free consultation or a trial class,
- for the purpose of concluding a contract, purchasing a pass online, registering an account and taking steps prior to concluding a contract,
- for the purpose of performing the membership agreement and handling the pass, bookings, visits and the Client Zone,
- for the purpose of handling payments, including recurring card payments and direct debit;
- on the basis of Article 6(1)(c) GDPR for the purpose of fulfilling the statutory obligations incumbent on the Controller, where the Controller:
- is required to fulfil obligations in the area of tax law,
- is required to archive documents for the period specified in the applicable provisions,
- is required to examine requests, complaints and claims,
- is required to make data available at the request of the competent state authorities;
- on the basis of Article 6(1)(f) GDPR, where this is justified by the legitimate interest of the Controller, in the case of:
- carrying out marketing activities, in particular by addressing to existing customers information concerning products or services similar to, or connected with, the products or services used by the customer under an existing contractual relationship – without the use of communication channels for which the law requires the recipient’s prior consent – until an objection is raised to the processing of personal data for this purpose,
- maintaining social media profiles and providing information about the Controller’s activities,
- market and public opinion research, unless you object to the use of your data,
- adapting the content of the Website to the needs of Users, in view of safeguarding the legitimate interests of the Controller in the best possible functioning of the Website and a user-friendly and efficient visit to the Website,
- ensuring IT security and the operation of IT systems,
- communicating and resolving a matter addressed to the Controller via the electronic form available on the Website, by e-mail or by traditional correspondence,
- handling requests, complaints or claims,
- the possible establishment and pursuit of claims or defence against claims,
- archiving documents, in relation to documents whose retention period is not regulated by law.
The sending by the Controller of commercial information by electronic means to the e-mail address provided, once consent has been obtained, takes place in accordance with Article 398 of the Act of 12 July 2024 – Electronic Communications Law.
The use by the Controller of telecommunications terminal equipment, including mobile telephones, computers and automated calling systems, for the purposes of direct marketing takes place in accordance with the Act of 12 July 2024 – Electronic Communications Law, once your consent has been obtained.
Consent to receive commercial information may be withdrawn at any time by using the unsubscribe link included in every message or by contacting the Controller at iod@strongpilates.pl.
4. Scope of the data processed
4.1. Contract and provision of services
- identification and contact data, in particular first name, surname, date of birth, address, e-mail and telephone number – solely to the extent required for the given contract or service,
- membership number, home club, type and validity of the pass, history of bookings, entries and use of services,
- data of the payer, statutory representative or legal guardian, where the contract concerns a minor,
- settlement data, bank account number, payment token, payment identifier and status; full card details are transferred directly to the payment operator,
- the content of enquiries, complaints, claims and damage reports together with the documents needed to examine the matter.
4.2. Website, forms and social media
When the Website is used, data may be generated concerning the device and browser, the IP address, server logs, cookie identifiers, the history of content displayed and the information provided in a form. On social media, the Controller receives the data made available by the User in accordance with the settings of the given platform.
4.3. Sources of data
Data comes directly from the User, from the payment operator as regards transaction status, from the device and operating system, and from the browser or the tools used on the Website.
4.4. Required and optional data
Fields marked as required are needed in order to conclude or perform a contract, identify membership, make a payment or handle a selected function. Failure to provide them may result in the inability to conclude a contract or to use a given function. A photograph, marketing, analytics, diagnostics and permissions unrelated to the core service are optional.
4.5. Special categories of data
The Controller does not collect health data via the Website. The User should not enter such data in free-text fields, unless it is necessary in order to examine an incident, damage or claim. In such a case the basis for processing is Article 9(2)(f) GDPR.
5. Data recipients
Personal data may be transferred to entities supporting the Controller’s day-to-day business processes with which the relevant data processing agreements have been signed, i.e. suppliers responsible for the operation of IT systems and equipment (including the supplier of the studio management and customer service system Glofox, operated by ABC Fitness Solutions), hosting providers, entities providing accounting, legal, marketing, postal and courier services, and archiving entities.
Personal data is not transferred to other entities for marketing purposes, nor to third parties for the purpose of their own activities.
The Controller reserves the right to disclose selected information concerning the data subject to the competent authorities or to third parties which request such information, on an appropriate legal basis and in accordance with applicable law.
| Recipient | Scope | Role |
|---|---|---|
| Hosting, API and IT support | maintenance of the Website | processors acting on the documented instructions of the Controller, provided that they do not determine the purposes independently |
| Google Ireland Limited and the relevant Google entities | Google Analytics, Google Ads – only within the scope of active services | the role depends on the specific service and terms; the configuration must be confirmed |
| Providers of accounting, legal services, archiving, post, communications and insurance | ancillary services, settlements, correspondence, archiving and damage handling | processors or separate controllers within the scope of their own obligations |
| Meta Platforms Ireland, LinkedIn Ireland, Google | maintaining profiles, embedded content, measurement and marketing – subject to consent where required | separate controllers or joint controllers within the scope determined by the platform’s terms |
| TikTok Technology Limited | maintaining profiles, embedded content, measurement and marketing – subject to consent where required | separate controllers or joint controllers within the scope determined by the platform’s terms |
| Glofox (ABC Fitness Solutions) | supplier of the studio management and customer service system | processors acting on the documented instructions of the Controller, provided that they do not determine the purposes independently |
| Courts, law enforcement authorities, tax authorities and other authorised bodies | solely within the scope resulting from a binding request or provision of law | recipients authorised on the basis of law |
6. Data retention period
The period for which the Controller processes data depends on the type of service provided and the purpose of the processing. As a rule, personal data will be stored for the following period:
- where personal data is processed on the basis of consent – until that consent is withdrawn, subject to the proviso that the data will continue to be processed only to the extent necessary for the Controller to pursue claims and to defend against such claims – until the expiry of the limitation period,
- where the basis for the processing of data is a contract concluded with the Controller – for the entire duration of that contract and, in addition, to the extent permitted by law, for the purpose of the Controller pursuing claims and defending against such claims – until the expiry of the limitation period,
- where the basis for the processing of personal data is a legitimate interest pursued by the Controller – for as long as the data is necessary for the purposes for which it is processed, or for as long as required by law,
- where personal data is processed for marketing purposes:
- on the basis of consent to the use of means of electronic communication – until that consent is withdrawn or an objection to the processing of personal data is raised, whichever occurs first,
- on the basis of the legitimate interest of the Controller – until an objection is raised,
7. Transfer of data outside the European Economic Area
As a rule, the Controller does not transfer data outside the European Economic Area. However, in connection with the use of analytical and marketing tools of external providers and of IT systems of providers having affiliated entities outside the EEA, we inform you that some data may be transferred outside the territory of the European Economic Area. Such a transfer of data may take place on the basis of an adequacy decision adopted by the European Commission, i.e. e.g. for organisations participating in the EU-U.S. Data Privacy Framework, or on the basis of standard contractual clauses in accordance with a decision of the European Commission, or on the basis of the explicit consent of the data subject.
The derogations under Article 49 GDPR are not a basis for regular and repetitive technical transfers. Information on the mechanism applicable to a specific recipient and a copy of the safeguards applied may be obtained at iod@strongpilates.pl.
8. Rights relating to the processing of data
Data subjects have the following rights:
- Right of access to personal data and to information on its processing. The data subject has the right to obtain from the Controller: confirmation that it processes personal data; access to that personal data; a copy of the personal data, as well as the information set out in detail in Article 15(1) GDPR.
- Right to rectification of data. The data subject has the right to request that the Controller rectify without undue delay personal data which is inaccurate, or update it, and that it complete incomplete personal data.
- Right to restriction of the processing of data. The data subject has the right to request that the Controller restrict the processing of personal data: if they contest the accuracy of the personal data; if the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of its use instead; if the Controller no longer needs the personal data for the purposes of the processing, but it is required by the data subject for the establishment, exercise or defence of claims; if the data subject has objected to the processing. Where the right to restriction of the processing of personal data is exercised, the Controller may continue to process it on the terms set out in Article 18(2) GDPR.
- Right to data portability. The data subject has the right to receive the personal data or to authorise the Controller to transmit it to another controller in a structured, commonly used format, where such transmission is technically feasible. The Controller will transfer only personal data which jointly meets the following conditions: the processing is carried out by automated means, i.e. the personal data is not in paper form, and the data is processed on the basis of consent or in connection with a concluded contract.
- Right to erasure of data. The data subject has the right to request that the Controller erase personal data concerning them where the data is no longer needed to achieve the purposes for which it was collected or otherwise processed, consent has been withdrawn and there is no other legal basis for the processing, an effective objection has been raised, the data has been processed unlawfully, or erasure results from a legal obligation, taking into account the exceptions under Article 17(3) GDPR.
- Right to object to the processing of data for marketing purposes. The data subject has the right to object to the processing of personal data for the purposes of direct marketing, including profiling, to the extent that the processing is related to such marketing.
- Right to object to the processing of data for other purposes. The data subject has the right to object to the processing of personal data based on a legitimate interest pursued by the Controller or by a third party, including profiling. The raising of an objection means that such personal data may no longer be processed, unless the Controller demonstrates the existence of compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or grounds for the establishment, exercise or defence of claims.
- Right to withdraw consent. The data subject has the right to withdraw at any time the consent on the basis of which their personal data is processed, which however does not affect the lawfulness of the processing carried out before that consent was withdrawn.
- Right to lodge a complaint. The data subject has the right to lodge a complaint with the President of the Personal Data Protection Office (address: ul. Stanisława Moniuszki 1A, 00-014 Warsaw, Poland) if they consider that the processing of personal data infringes the provisions of the GDPR or other provisions on the protection of personal data.
- Right to manage cookie settings and other technologies. The data subject has the right to manage consent to the use of cookies and other technologies by means of the browser settings and the cookie banner on the Website. The data subject has the right to configure their browser so that cookies are deleted from the hard drive, to prevent new cookies from being placed, or to receive notifications so that no cookie is placed without the express consent of the data subject. Changing cookie settings (disabling their acceptance) may make it impossible to use parts of the Website or to display some information. Detailed information on this subject can be found at the following links:
- Microsoft Edge: https://support.microsoft.com/en-us/microsoft-edge/delete-cookies-in-microsoft-edge-63947406-40ac-c3b8-57b9-2a946a29ae09
- Firefox: https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer
- Google Chrome: https://support.google.com/chrome/answer/95647?hl=en
- Opera: https://help.opera.com/en/latest/web-preferences/
- Safari: https://support.apple.com/en-gb/guide/safari/sfri11471/mac
Requests may be submitted in writing to the Controller’s address, to iod@strongpilates.pl, or by using the function provided for the given right. The Controller may ask for the data needed to confirm identity. A reply is provided without undue delay, as a rule within one month.
9. Automated decisions and profiling
The Controller does not take decisions based solely on automated processing which produce legal effects or similarly significantly affect a person within the meaning of Article 22 GDPR.
Once consent has been given to the analytical or marketing technologies of the Website, profiling may take place which serves to select content or to assess the effectiveness of campaigns. It does not lead to decisions within the meaning of Article 22 GDPR.
10. Information on the voluntary nature of providing personal data
Where any form available on the Website is completed, the Controller collects and processes the data provided, which is adequate, relevant and limited to what is necessary to achieve the purposes for which it is processed, taking into account the principle of “data minimisation” in accordance with the GDPR.
Providing personal data is voluntary; however, in some cases providing data is necessary in order to examine an enquiry or to arrange a free consultation or training session.
11. Security of personal data
The Controller, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, carries out a risk analysis at specified intervals in order to ensure that personal data is processed in a secure manner and that it is accessible only to authorised persons and only to the extent necessary in view of the tasks they perform.
12. Social media platforms
The Controller processes the personal data of Users visiting the Controller’s profiles maintained on social media (Facebook, Instagram, YouTube, LinkedIn, TikTok). This data is processed solely in connection with the maintenance of the profile, including for the purpose of informing Users about the Controller’s activity and promoting various types of events, services and products. The legal basis for the processing is the legitimate interest of the Controller (Article 6(1)(f) GDPR) consisting in the promotion of its own brand.
13. Cookies
In addition to personal data, the Controller also collects information by means of cookies. Cookies are small text files installed on the terminal device (e.g. computer, tablet, smartphone) of the User browsing the Website. During a visit to the Website, cookies are collected automatically by the system through the internet browser. The data contained in these files comprises the IP address, browser type, operating system type, the region for which the pages are viewed, the history of content viewed on the Website and the analysis of events on the Website.
The legal basis for the processing of personal data in the above manner is the User’s consent and, as regards the files necessary for the operation of the Website, the legitimate interest of the Controller consisting in ensuring high quality and security of services.
The Website uses cookies and similar mechanisms for storing and reading information on a device. Detailed information on the current names, providers and purposes is available in the “Cookie settings” panel.
| Category | Purpose | Basis |
|---|---|---|
| Necessary | session, security, log-in, remembering choices and functions requested by the User | Article 399(3) of the Electronic Communications Law; respectively Article 6(1)(b) or (f) GDPR |
| Preference | remembering settings which are not necessary to perform the requested function | prior consent – Article 399 of the Electronic Communications Law and Article 6(1)(a) GDPR |
| Statistical | measuring use of the Website and improving its operation | prior consent – Article 399 of the Electronic Communications Law and Article 6(1)(a) GDPR |
| Marketing | campaign measurement, tailored advertising and remarketing | prior consent – Article 399 of the Electronic Communications Law and Article 6(1)(a) GDPR; for sending marketing communications also Article 398 of the Electronic Communications Law |
Cookies other than necessary ones remain disabled by default. A refusal may not block access to basic content and services which do not require the given technology.
Consent may be changed or withdrawn at any time through the permanently available “Cookie settings” link. Withdrawal stops any further writing or reading of non-essential information; data collected earlier is handled in accordance with the applicable basis and retention period.
14. Analytical and marketing tools used by the Controller
Google Analytics
The Controller uses the Google Analytics analytical tools, which are cookies of Google Ireland Ltd. collecting information on the way in which the User uses the Website, such as the subpages that have been displayed, the time spent on the Website or the transitions between individual subpages. Google Analytics cookies collect demographic data and data on interests. Detailed information on the scope and rules of data collection in connection with this service can be found at the following link: https://www.google.com/intl/en/policies/privacy/partners.
Google Ads
The Controller uses the Google Ads tools of Google Ireland Ltd., thanks to which it may present its offer within the Google search engine and on websites that form part of the Google advertising network. A User who enters specific terms in the search engine may be shown an advertisement of the Controller correlated with that term. Within Google Ads, the Controller analyses the effectiveness of advertisements published on Google pages, thanks to which the offers are better matched to Users’ expectations. Detailed information is available at the following link: https://policies.google.com/technologies/ads?hl=en.
Meta Pixel
The Controller uses the Meta Pixel marketing tools, which are cookies of Meta Platforms Ireland Ltd. enabling the targeting of personalised advertising on the Facebook and Instagram platforms. The Controller holds information solely on the User’s actions taken within its Website. Nevertheless, Meta may, entirely independently of the Controller, combine this information with other information collected in connection with the User’s use of the Meta platforms and use it for its own purposes, including marketing purposes. Detailed information: https://www.facebook.com/help/443357099140264?helpref=about_content.
The Controller uses the LinkedIn marketing tools, managed by LinkedIn Ireland Unlimited Company. Every call-up of the Controller’s Website which contains LinkedIn functions results in a connection being established with LinkedIn servers. LinkedIn receives the information that the User has visited the Website by means of the IP address. LinkedIn may assign the User’s visit to the Website to their account on the LinkedIn service. The Controller has no knowledge of the content of the data transferred or of how LinkedIn uses it. Detailed information: https://www.linkedin.com/legal/privacy-policy.
Glofox
Data provided by the User in the forms on the Website may be saved in the Glofox system, which the Controller uses to manage its customer database and to communicate with customers. The system provider processes the data solely on the instructions of the Controller, on the basis of the data processing agreement concluded.
15. Social media plugins
Facebook plugin
Plugins for the Facebook social networking service are integrated with the Website. The Facebook plugin on the Website is marked with the Facebook logo. The plugin will connect the User directly with the Controller’s profile on the Facebook server. Facebook may then obtain the information that the User has visited the Website from their IP address. Where the User visits the Website while logged in to their Facebook profile, Facebook will record the information about the visit. Even if the User is not logged in, Facebook is able to obtain information about the IP address. The Controller has no knowledge of the content of the data transferred or of its use by Facebook. Privacy policy of the platform: https://www.facebook.com/about/privacy/.
Instagram plugin
Plugins for the Instagram service (Meta Platforms Ireland Ltd.) are integrated with the Website. The Instagram plugin on the Website is marked with the Instagram logo in the form of the “Instagram Camera”. Clicking this button will result in a direct connection being established with Instagram servers and will connect the User with the Controller’s profile. Instagram may then obtain the information that the User has visited the Website from their IP address, also where the User does not have a profile on the Instagram service or is not logged in. Privacy policy: https://help.instagram.com/155833707900388/. The loading of Instagram plugins may be blocked by means of browser add-ons.
YouTube plugin
The Controller’s Website has been integrated with the video service provider YouTube (YouTube LLC., a company belonging to Google Ireland Ltd.). Actively clicking the plugin button results in a connection being established with YouTube servers. If the User is logged in to their YouTube account, YouTube assigns the information about the visit to the Controller’s Website to the User’s personal account. Clicking the video play button also assigns information about this to the YouTube user’s account. Privacy policy: https://policies.google.com/privacy?hl=en. Where the User does not wish such an association to be made, they should log out of their YouTube and Google account beforehand and delete the cookies of these companies before visiting the Website.
LinkedIn plugin
Plugins of the LinkedIn service (LinkedIn Ireland Unlimited Company) may be integrated with the Website. Their call-up results in a connection being established with LinkedIn servers, which receive the information about the visit to the Website together with the User’s IP address. Privacy policy: https://www.linkedin.com/legal/privacy-policy.
TikTok plugin
Plugins for the TikTok service (TikTok Technology Limited) are integrated with the Website. The TikTok plugin on the Website is marked with the TikTok logo in the form of the “TikTok Note”. Clicking this button will result in a direct connection being established with TikTok servers and will connect the User with the Controller’s profile. TikTok may then obtain the information that the User has visited the Website from their IP address, also where the User does not have a profile on the service or is not logged in. Privacy policy: https://www.tiktok.com/legal/page/eea/privacy-policy/en.
Note concerning profiles: Persons using social networking platforms have their own rights (including the right to edit their profile or to manage their data on the platform). With regard to these profiles, the Controller acts solely within the limits of its technical and legal possibilities and in accordance with the rules of the platform.
16. Amendments to the Privacy Policy
The Policy is reviewed on an ongoing basis and updated where necessary. This version is effective as of 11 September 2026.