Privacy Policy
1. Controller
The controller for the processing of personal data within the meaning of the GDPR is:
Matthias Rottmann, autónomo
PHOENIX Private Health Coaching
Avenida Diego Ramírez Pastor 277B, 03182 Torrevieja (Alicante), Spain
Email: private@phoenix-personaltraining.com
Telephone / WhatsApp: +34 624 604 480
NIF/NIE: Y4233457E
No Data Protection Officer has currently been appointed.
2. Scope
This policy explains the processing of personal data when you use this website and when you contact us by email, telephone or WhatsApp.
3. Processing activities at a glance
| Processing | Data / purpose | Legal basis | Retention period |
|---|---|---|---|
| Technical provision and website security | Server log data (IP address, date/time, requested page, browser). Purpose: secure delivery and error analysis. | Article 6(1)(f) GDPR | Normally no longer than 30 days. |
| Enquiries | Name, contact details, message content. Purpose: responding to an enquiry and taking pre-contractual steps. | Article 6(1)(b) and (f) GDPR | Without a contract: up to 12 months after the enquiry is closed. |
| Contract and client administration | Master data, communication data, agreed services, invoicing and payment data. Purpose: coaching delivery, billing and statutory compliance. | Article 6(1)(b) and (c) GDPR | Contract period + statutory retention periods (generally 6 years in Spain). |
| Health-related information in coaching | Voluntarily supplied information about capacity, symptoms, injuries or limitations. Purpose: safe, personalised training planning. | Article 6(1)(a) together with Article 9(2)(a) GDPR (explicit consent) | Coaching period + up to 3 years. |
4. Health data: special notice
Health data is particularly sensitive. Please do not send medical records, diagnoses or detailed health information through a general contact form. Where such information is necessary for individual coaching, it will only be collected after separate explicit consent, which can be withdrawn at any time with future effect.
5. Recipients and processors
Your data is disclosed only where necessary and lawful. Recipients may include:
- technical providers for hosting, maintenance, email infrastructure and backups;
- tax advisers, bookkeeping providers, banks and payment providers;
- public authorities where required by law or to establish, exercise or defend legal claims.
Personal data is not sold.
6. WhatsApp
The website contains a link to contact us via WhatsApp. This is an external link; a connection to WhatsApp is only made when you activate it. WhatsApp and Meta process data under their own privacy policies, and processing outside the EEA cannot be ruled out. Do not send medical records or other sensitive health data via WhatsApp unless expressly agreed in advance.
7. International transfers
The website is operated so that hosting, email infrastructure and backups are located in the EEA, or so that any transfer to a third country is covered by an adequacy decision under Article 45 GDPR or appropriate safeguards under Article 46 GDPR.
8. No automated decision-making
No automated decision-making, including profiling, is carried out that produces legal effects or similarly significantly affects you.
9. Your rights
Subject to the GDPR, you have the rights of access, rectification, erasure, restriction of processing, data portability and objection to processing based on Article 6(1)(e) or (f) GDPR. You may withdraw consent at any time with future effect. To exercise your rights, contact private@phoenix-personaltraining.com.
You also have the right to lodge a complaint with the competent supervisory authority. In Spain, this is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, Spain.
10. Security
Appropriate technical and organisational measures are used to protect personal data against loss, destruction, unauthorised access, alteration or disclosure.
11. Cookie notice
In its basic version, this website operates without analytics, marketing or advertising cookies. It uses only technically necessary storage where required for secure delivery or to save your cookie choice. No consent is required for strictly necessary cookies.
12. Updates
This privacy policy will be updated where the services used, processing activities or legal position change. The version published on the website at the relevant time applies.