Privacy policy

How we handle your data – on this website, when you sign up online and in the members’ area.

This translation is provided for your information. The German version is legally binding.

This policy explains what data we process when you visit this website, become a member online or use the members’ area, and what rights you have in this respect.

Key points at a glance

  • Without your consent, we do not load anything from third-party servers into your browser: no fonts from Google, no maps, no videos and no social media buttons.
  • Advertising and measurement services from Meta, TikTok and Google only run if you consent in the cookie banner. You can change your choice at any time.
  • If you become a member online, we pass your details to our membership management system so that your contract can be concluded. They are not stored permanently on this website itself.

Data controller

The controller responsible for processing your data for the purposes of the General Data Protection Regulation (GDPR) is:

Company
Mila Moon GmbH
represented by its managing director, Benjamin von Krockow
Address
Industriestraße 7
63801 Kleinostheim
Phone
06021 1304580
Email
support@milamoon.de

Data protection officer

Our data protection officer is Sandy Wilde, Am Glockenturm 1, 63814 Mainaschaff. You can contact her at datenschutz@milamoon.de.

When you visit this website

When you access this website, your browser sends technical data without which no connection could be established. Our hosting provider processes this data in server log files:

  • your IP address
  • the date and time of access
  • the URL requested and the amount of data transferred
  • your browser, its version and your operating system
  • the page you visited previously, if your browser sends this information

We use this data to deliver the website, keep it stable and detect attacks. The legal basis is our legitimate interests in operating the website securely (Art. 6(1)(f) GDPR). We do not combine this data with other data or use it to analyse your behaviour.

Hosting

This website is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. Vercel processes the data listed above on our behalf under a data processing agreement in accordance with Art. 28 GDPR.

Fonts, images and videos

Our font and all images and videos are stored on our own server. This means that your visit does not create any connection to Google or any other provider, and your IP address is not transmitted to them.

Becoming a member online

When you take out a membership on milamoon.de, we ask for the details we need for your contract:

  • title, first name and surname
  • date of birth
  • address
  • email address and mobile number
  • IBAN and account holder’s name
  • your studio, your plan and the extras you choose

We process this data in order to enter into and perform your contract (Art. 6(1)(b) GDPR). Without it, we cannot enter into a contract with you.

While you are completing the sign-up form, your details remain in your browser, except for the two features described below. When you click “Buy membership”, they are sent via our server to our membership management system and stored there, not on this website. Before we create your contract, we use your email address to check whether you already have an account with us, so that a second membership is not created by mistake.

Distance to the studio

When you choose your studio, your browser asks whether you want to share your location with us. If you allow this, your browser calculates the straight-line distance between you and the studio and displays it. Your location stays on your device: we do not receive it and do not store it, not even in your browser. The legal basis is the consent you give when your browser asks you (Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG)). Sharing your location is voluntary – if you do not share it, the only difference is that the distance is not shown. You can revoke this permission at any time in your browser settings.

Address suggestions

As you type your street, we suggest matching addresses, and when you enter a postcode, we add the town. To do this, our server sends the street, house number and town you have typed, or the postcode, to two open address services: the OpenPLZ API (openplzapi.org) and Photon by komoot GmbH (photon.komoot.io). These services do not receive your IP address, name or email address. The legal basis is our legitimate interests in fast, error-free data entry (Art. 6(1)(f) GDPR). You can also ignore the suggestions and type in your address yourself.

Checking your bank details

Once you have entered your IBAN, we check it via our membership management system and show you the name of your bank. This means that a typing error is spotted before it causes a direct debit to fail (Art. 6(1)(b) GDPR).

Our membership management system

We manage your membership using software provided by Magicline GmbH, Raboisen 6, 20095 Hamburg. Magicline processes your data on our behalf under a data processing agreement in accordance with Art. 28 GDPR. Magicline also stores the data on servers operated by Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, 1855 Luxembourg, through which it may be transferred to the USA (see “Transfers to the USA”).

This system holds the data from your contract: name, address, contact details, date of birth, start date and term, fees and bank details. Any data added in the studio, such as check-ins, will be described here before the studio opens. We only collect information such as a photo or data concerning your health if you give your explicit consent.

Login link and members’ area

After you have signed up, we will email you a link that you can use to log in to the members’ area. The link is valid for 15 minutes and can only be used once. We use the email service Resend to send it. Until you use the link, your email address is held for this purpose in a data store provided by Upstash, for no longer than 15 minutes.

When you log in, we use your email address to find your account in our membership management system. If there is more than one account with the same email address, we will ask for your membership number.

In the members’ area, you can view your data from our membership management system – contract, fees, bookings and documents – and send changes and requests to it, such as a cancellation. To ensure that the pages load quickly, we keep retrieved data on our server for no longer than five minutes. The legal basis is Art. 6(1)(b) GDPR.

A cookie keeps you logged in (see below). If you log out on all devices, we store the time of logout for 90 days so that earlier logins are no longer valid.

Cancelling or withdrawing from your contract

You can use “Cancel contract here” and “Withdraw from contract here” to cancel or withdraw from your contract without logging in. To do so, we ask for your first name and surname, date of birth, membership number (optional for withdrawals) and the email address for the confirmation – and, for cancellations, also the type and date of cancellation and, if you provide them, a reason and, for a cancellation for good cause, your grounds.

Our server uses your membership number to find your contract in our membership management system and records the cancellation or withdrawal there. For a cancellation for good cause, a withdrawal without a membership number, or if we cannot clearly identify your contract, your notice is sent by email to our team, who will match it manually. We send you a confirmation of receipt by email via Resend. Your details are not retained on this website. The legal bases are your contract (Art. 6(1)(b) GDPR) and our legal obligation to enable cancellation and withdrawal online and to confirm them (Art. 6(1)(c) GDPR, Section 312k of the German Civil Code (BGB)).

If you cancel for good cause, you may choose to attach supporting documents, such as a medical certificate. These are sent to our team with your cancellation via Resend and, if we can clearly identify your contract, we file them with your account in our membership management system. They are not retained on this website. If they contain health data, we process this data only to assess your cancellation (Art. 9(2)(f) GDPR) and only for as long as we need it for that purpose and to comply with statutory retention obligations.

Protection against misuse

To prevent automated misuse of our forms, we count how often each IP address uses the sign-up, the bank details check, the address suggestions, cancellation and withdrawal, the contact form, login and the saving of your cookie preferences. For login, we also count per email address; in that case, both the IP address and the email address are stored only as hashed values, not in plain text. The counters are kept in Upstash’s data store and expire after one hour at the latest. The legal basis is our legitimate interests in operating the website securely (Art. 6(1)(f) GDPR).

Protected preview access

Until the website is fully launched, part of it is protected by a password that is only given to those involved. When you enter the password, we check it and, if it is correct, set a technically necessary cookie that remembers your access for 30 days. The legal basis is our legitimate interests in not making unfinished content publicly available (Art. 6(1)(f) GDPR).

Cookies and storage in your browser

Without your consent, we only store in your browser what the website needs in order to function: a few cookies and entries in your browser’s storage. We do not need your consent for this (Section 25(2) no. 2 TDDDG). The entries in your browser’s storage do not leave your device. The cookies used by the other services are listed under “Statistics, advertising and performance measurement”.

Your cookie preferences (Cookie on milamoon.de, 12 months)
Stores the choices you make in the cookie banner, together with a random identifier, so that we do not ask you again on every visit. We ask you again after twelve months, and also whenever a service is added.
Members’ area login (Cookie on milamoon.de, 90 days)
Keeps you logged in to the members’ area. It contains your account ID, secured against tampering, but not your name or email address. We delete it when you log out.
Preview access (Cookie on milamoon.de, 30 days)
Remembers that you have entered the preview password while parts of the website are password-protected. It contains only a hashed value, not your name or email address.
Your sign-up selections (Browser session storage, until sign-up is complete, or at the latest until you close the tab)
Remembers the studio, plan and extras you select during online sign-up so that they are kept if the page is reloaded. It contains no personal details and is deleted once you have signed up.
Header state (Browser session storage, until you close the tab)
Remembers whether the header was collapsed so that it does not briefly jump open when the page is reloaded.

You can delete all entries at any time in your browser settings. Each cookie is listed with its name, provider and duration on our Cookies page.

Statistics, advertising and performance measurement – only with your consent

The following services are only loaded once you have given your consent in the cookie banner. The legal basis is your consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG). You can withdraw your consent at any time via the “Cookies” link at the bottom of every page; the services will then no longer be loaded, and we will delete their cookies on our domain.

So that we can demonstrate that you made a choice and what it was (Art. 7(1) GDPR), we record every choice made in the banner: the random identifier from your cookie, the time, the banner version and your selection, without your IP address or name. These records are stored in Upstash’s data store and deleted after three years. The legal basis is our legal obligation to provide this proof (Art. 6(1)(c) GDPR).

Meta-Pixel

The Meta Pixel allows us to see whether our ads on Facebook and Instagram are effective – for example, whether a membership was taken out after an ad was clicked – and to show you ads there that relate to your visit. For this purpose, your browser loads a script from Meta. The script sends Meta your IP address, information about your browser and device, the pages you visit and actions such as signing up, and sets cookies. If you are logged in to Facebook or Instagram, Meta can link your visit to your account.

The provider is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. We are joint controllers with Meta for the collection and transmission of the data (Art. 26 GDPR; joint controller agreement); Meta alone is responsible for any subsequent processing. Meta may transfer data to the USA and is certified under the EU-US Data Privacy Framework. For more information, see Meta’s Privacy Policy.

Cookie storage period: up to 90 days.

TikTok-Pixel

The TikTok Pixel allows us to see whether our ads on TikTok are effective and to show you ads there that relate to your visit. For this purpose, your browser loads a script from TikTok. The script sends TikTok your IP address, information about your browser and device, the pages you visit and actions such as signing up, and sets cookies.

The provider is TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland. TikTok also uses the data for its own purposes and may process it outside the EU; such transfers are based on the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR). For more information, see TikTok’s privacy policy at tiktok.com/legal.

Cookie storage period: up to 13 months.

Google Ads

Google Ads allows us to see whether our ads on Google lead to sign-ups (conversion tracking) and to show you ads on Google and partner websites that relate to your visit (remarketing). For this purpose, your browser loads scripts from Google. These scripts send Google your IP address, information about your browser and device, the pages you visit and actions such as signing up, and set cookies.

We integrate Google Ads and Google Analytics via Google Tag Manager. Google Tag Manager itself does not set any cookies or analyse any data, but it loads the two services and, in doing so, transmits your IP address to Google. For this reason, it is also only loaded once you have consented to one of the two services, and it only enables the service you have consented to.

The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google may transfer data to the USA and is certified under the EU-US Data Privacy Framework. For more information, see Google’s Privacy Policy.

Cookie storage period: up to 13 months.

Google Analytics

Google Analytics shows us, in aggregated form, which pages are read, where visitors come from and where they leave the website, so that we can identify what is helpful on the website and what is not. For this purpose, your browser loads a script from Google via Google Tag Manager (see Google Ads). The script sends Google your IP address, information about your browser and device and the pages you visit, and sets cookies. According to Google, Google Analytics uses your IP address only to determine your approximate location and does not store it; we do not see any individuals, only aggregated figures.

The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google processes the data on our behalf as a processor (Art. 28 GDPR). Google may transfer data to the USA and is certified under the EU-US Data Privacy Framework. For more information, see Google’s Privacy Policy.

Cookie storage period: up to 2 years.

When you write to us, call us or use the contact form

If you contact us by email or phone (details in our Imprint) or via our contact form, we process your details in order to respond to your enquiry. In the contact form, these are your email address, whether you are a member or interested in joining, your name, your reason for contacting us (if you are a member) and, if you provide it, your membership number, as well as the subject, your message and any files you attach. We send the message, including any attachments, to our inbox via the email service Resend; none of it is retained on this website. We send a brief confirmation of receipt to your email address via Resend, without repeating your details.

If you contact us because you are interested in joining, we create an entry for you with your name, email address and message in our membership management system at Magicline, so that your studio can advise you on membership and a trial session.

The legal basis is Art. 6(1)(b) GDPR if your enquiry concerns a contract (if you are interested in joining, a membership), and otherwise our legitimate interests in responding to your enquiry (Art. 6(1)(f) GDPR). We delete the data once the matter has been concluded, provided that no statutory retention obligations prevent this.

Our emails are handled via Microsoft 365, provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland, which processes them on our behalf (Art. 28 GDPR).

Transfers to the USA

Vercel, Upstash and Resend are US-based providers, and data may also be transferred to the USA via Amazon Web Services (membership management) and Microsoft (email). These transfers are based on the European Commission’s adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR) where the provider is certified under it, and otherwise on the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR).

How long we keep your data

We delete your data as soon as we no longer need it for the purpose for which we process it; the retention periods for cookies, counters and the login link are set out above. We keep the data from your contract for the duration of your membership and thereafter for as long as required by commercial and tax law, usually six to ten years.

Your rights

You have the following rights against us:

  • Information about what data we process about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Provision of your data in a portable format (Art. 20 GDPR)
  • Objection to processing based on our legitimate interests (Art. 21 GDPR)

You can withdraw any consent you have given at any time, with effect from that point onwards. This does not affect the lawfulness of processing carried out before the withdrawal. To withdraw your consent, simply email us at datenschutz@milamoon.de.

Right to lodge a complaint

If you believe that we are not processing your data lawfully, you can lodge a complaint with a data protection supervisory authority, for example the authority where you live. The supervisory authority responsible for us is the Bayerisches Landesamt für Datenschutzaufsicht (Bavarian State Office for Data Protection Supervision), Promenade 18, 91522 Ansbach.

Changes to this policy

We will update this policy when the website changes, and at the latest when the studio opens. The version published on this page is the one that applies.

Last updated: September 2026