Privacy Policy
Last updated on September 9, 2026
This privacy policy applies to our websites b-42.com, elite.b-42.com, pro.b-42.com, and prevention.b-42.com. If you use the B42 App, the separate B42 App Privacy Policy applies. The separate Nutrition App Privacy Policy applies to B42 Nutrition for Footballers. The separate CoachZone Privacy Policy applies to B42 CoachZone (teams.b-42.com).
1. General Information
The following information provides a simple overview of what happens to your personal data when you visit our websites. Personal data means any data that can identify you personally. Detailed information is provided in the full privacy policy below.
2. Data Collection on Our Websites
2.1. Who is responsible for data collection?
Data on these websites is processed by the website operator. Contact details are provided in section 3.2.
2.2. How do we collect your data?
Some data is collected when you actively provide it to us, for example by entering information in a contact or registration form or purchasing a subscription. Technical data is also collected automatically when you visit our websites (e.g. browser, operating system, and time of page access).
2.3. What data do we collect and why?
We process the following categories of personal data on our websites:
Contact data
Email address, name, and other information you provide through forms on our websites (e.g. course registration and contact inquiries). We use this data to handle your inquiry or inform you about services you have booked. This data is deleted after 3 years unless a statutory retention obligation requires otherwise.
Purchase information
Subscriptions or courses can be purchased at elite.b-42.com, pro.b-42.com, and prevention.b-42.com. We process information about the payment provider, subscription duration and price, and the payment number assigned by the payment provider. We do not store credit card information ourselves.
Device information and technical data
When you visit our websites, technical data is collected automatically, including IP address, browser type and version, operating system, referrer URL, pages visited, date and time of the visit, and time spent. This data is necessary for secure website operation.
Behavioral and usage data
With your consent, we analyze your usage behavior on our websites (e.g. areas clicked, page views, and session duration). The legal basis is Article 6(1)(a) GDPR. The tools used are described in section 6.
2.4. What rights do you have regarding your data?
You have the right at any time to obtain free information about the source, recipients, and purpose of your stored personal data, and the right to rectification or erasure. Contact us at any time with further questions. You also have the right to lodge a complaint with the competent supervisory authority.
2.5. Analytics tools and third parties
When you visit our websites, your usage behavior may be statistically evaluated, but only after your express consent. Detailed information about the tools used is provided in section 6.
3. General Information and Mandatory Disclosures
3.1. Data protection
The operators of these websites take protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection provisions and this privacy policy.
Please note that data transmission over the internet may have security vulnerabilities. Complete protection against access by third parties is not possible.
3.2. Controller
The controller responsible for data processing on these websites is:
SFY GmbH
Industriestraße 15
84149 Velden
Germany
Phone: +49 160 97978139
Email: info@b-42.com
Represented by Managing Director Andreas Gschaider.
3.3. Withdrawal of your consent to data processing
Many processing operations are possible only with your express consent. You can withdraw consent at any time. An informal notification to us by email is sufficient. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
3.4. Right to lodge a complaint with the competent supervisory authority
In the event of data protection violations, you have the right to lodge a complaint with the competent supervisory authority. The competent authority is the state data protection commissioner of the federal state in which our company is based. A list of authorities is available at: www.bfdi.bund.de.
3.5. Right to data portability
You have the right to receive, or have a third party receive, data that we process automatically based on your consent or in performance of a contract, in a commonly used, machine-readable format.
3.6. SSL/TLS encryption
These websites use SSL/TLS encryption for security. You can recognize an encrypted connection by “https://” in your browser’s address bar and the padlock symbol.
3.7. Access, rectification, and erasure
Within the applicable statutory provisions, you have the right at any time to obtain free information about your stored personal data, its source and recipients, and the purpose of processing, and, where applicable, a right to rectification or erasure. Contact us at any time for this purpose.
3.8. Objection to advertising emails
We hereby object to the use of contact details published under legal notice requirements for sending advertising that has not been expressly requested. We reserve the right to take legal action if unsolicited advertising information is sent.
3.9. Transfers to third countries
Some services used on these websites are based in the USA. Where we transfer data to the USA, we rely on the European Commission’s adequacy decision for the EU-US Data Privacy Framework (DPF) of July 10, 2023, provided the relevant provider is DPF-certified. The applicable legal bases are stated for each service.
4. Technical Data Collection
4.1. Cookies and consent management
Our websites use cookies. Cookies are small text files stored on your device that save certain settings and data for exchange with our system.
We distinguish between technically necessary cookies required to operate the websites and optional cookies (e.g. for analytics), which we set only with your express consent. When you first visit our website, you see a cookie banner developed by us, through which you can grant or refuse consent. Your decision is stored locally in your browser; no data is transmitted to third parties in this process. You can withdraw consent at any time with effect for the future by opening the cookie settings through the corresponding link in our website footer.
Technically necessary cookies are set on the basis of Article 6(1)(f) GDPR. Optional cookies are set exclusively on the basis of your consent under Article 6(1)(a) GDPR.
4.2. Server log files
When you visit our websites, information transmitted by your browser is automatically stored in server log files:
- Browser type and version
- Operating system used
- Referrer URL
- Host name of the accessing computer
- Time of the server request
- IP address
This data is not combined with other data sources. The legal basis is Article 6(1)(f) GDPR. Server log files are automatically deleted after no more than 30 days.
5. Hosting
5.1. Vercel (b-42.com, elite.b-42.com, pro.b-42.com, prevention.b-42.com)
The website b-42.com and the subdomains elite.b-42.com, pro.b-42.com, and prevention.b-42.com are hosted by Vercel. The provider is Vercel Inc., 340 Pine Street, Suite 603, San Francisco, CA 94104, USA.
Vercel automatically processes technical data when operating these sites (particularly server log files as described in section 4.2). Data is processed on Vercel servers in the USA. Transfers are based on the EU-US Data Privacy Framework; Vercel is DPF-certified.
Vercel is used on the basis of Article 6(1)(f) GDPR. Vercel automatically deletes server log files after 3 days. We have concluded a data processing agreement with Vercel. Further information: vercel.com/legal/privacy-policy.
5.2. Webflow (blog reverse proxy)
Blog content at b-42.com/blog and b-42.com/post/* is delivered through a reverse proxy from an instance hosted by Webflow. The provider is Webflow, Inc., 398 11th Street, San Francisco, CA 94103, USA.
Webflow automatically processes technical data when operating this blog instance (particularly server log files as described in section 4.2). Data is processed on Webflow servers in the USA. Transfers to the USA are based on the EU-US Data Privacy Framework; Webflow is DPF-certified.
Webflow is used on the basis of Article 6(1)(f) GDPR. We have concluded a data processing agreement with Webflow. Further information: webflow.com/legal/privacy.
6. Analytics Tools
6.1. Google Analytics 4
These websites use Google Analytics 4 (GA4), a web analytics service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
GA4 uses cookies and similar technologies to collect and evaluate information about your website use (e.g. pages viewed, visitor sources, and time spent). GA4 anonymizes IP addresses by default before storing them.
GA4 is used only after your express consent. The legal basis is Article 6(1)(a) GDPR. Transfers to the USA are based on the EU-US Data Privacy Framework; Google LLC is DPF-certified.
The retention period for user data in our GA4 account is limited to 14 months, after which data is automatically deleted.
You can withdraw consent at any time through our website’s cookie settings. Alternatively, you can prevent collection using Google’s browser add-on: tools.google.com/dlpage/gaoptout.
We have concluded a data processing agreement with Google. Further information: support.google.com/analytics.
6.2. PostHog
These websites use PostHog, a product and web analytics tool provided by PostHog Inc. We use the EU cloud version; all data is processed and stored exclusively on servers within the European Union (Frankfurt, Germany). No personal data is transferred to third countries.
PostHog enables us to analyze how visitors use our websites (e.g. pages viewed, click paths, and session duration) to improve our offerings in a targeted way. Data is processed in pseudonymized form.
PostHog is used only after your express consent. The legal basis is Article 6(1)(a) GDPR. You can withdraw consent at any time through our website’s cookie settings. Collected usage data is automatically deleted after 12 months.
We have concluded a data processing agreement with PostHog. Further information: posthog.com/privacy.
6.3. Google Tag Manager
These websites use Google Tag Manager from Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Google Tag Manager is a tool for managing website tags through a central interface. Tag Manager itself does not set cookies or collect personal data. However, it enables other tags to be triggered that may themselves collect data; these are described separately in this privacy policy.
The legal basis is Article 6(1)(f) GDPR. Further information: Google Tag Manager Use Policy.
7. Plugins and Tools
7.1. YouTube
Our website b-42.com uses embedded videos from the Google-operated platform YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA.
When you access a page with an embedded YouTube video, a connection is established to YouTube’s servers, informing YouTube which page you visited. If you are logged into your YouTube account, YouTube can associate your browsing behavior directly with your profile. You can prevent this by logging out of your YouTube account beforehand.
The legal basis is Article 6(1)(f) GDPR. Transfers to the USA are based on the EU-US Data Privacy Framework; Google LLC is DPF-certified. Further information: policies.google.com/privacy.
7.2. Google Web Fonts
These websites use web fonts from Google LLC to display fonts consistently. When a page is accessed, your browser loads the required fonts from Google servers, allowing Google to learn of your visit through your IP address.
The legal basis is Article 6(1)(f) GDPR. Transfers to the USA are based on the EU-US Data Privacy Framework. Further information: developers.google.com/fonts/faq and policies.google.com/privacy.
8. Payment and Booking
8.1. RevenueCat
We use RevenueCat to manage subscriptions and in-app purchases on elite.b-42.com, pro.b-42.com, and prevention.b-42.com. The provider is RevenueCat, Inc., 633 Tasman Drive, San Jose, CA 95134, USA.
RevenueCat processes your subscription status, purchase time, selected plan, and an anonymized user ID. Credit card or bank account data is not transmitted to RevenueCat; it remains with the respective payment provider (App Store, Google Play, or Stripe).
Processing is based on Article 6(1)(b) GDPR (performance of a contract) and Article 6(1)(f) GDPR (legitimate interest in reliable subscription management). Transfers to the USA are based on standard contractual clauses under Article 46(2)(c) GDPR. We have concluded a data processing agreement with RevenueCat. Subscription data is stored for the duration of the contractual relationship and for 3 years after it ends (statutory limitation period). Further information: revenuecat.com/privacy.
8.2. Stripe
We use Stripe to process payments. The provider is Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA.
Stripe processes the data required for payment, including name, email address, billing address, and payment information (e.g. credit card details). Payment data is encrypted and transmitted directly to Stripe and is not stored on our servers.
Processing is based on Article 6(1)(b) GDPR (performance of a contract). Transfers to the USA are based on the EU-US Data Privacy Framework; Stripe is DPF-certified. We have concluded a data processing agreement with Stripe. Payment data is subject to statutory retention requirements under sections 146 and 147 of the German Fiscal Code (AO) and is stored for 10 years. Further information: stripe.com/de/privacy.
8.3. Calendly
A Calendly booking calendar is embedded as an iframe on our websites to book appointments and consultations. The provider is Calendly, LLC, 271 17th St NW, Suite 1000, Atlanta, GA 30363, USA.
As soon as you access a page with an embedded Calendly iframe, a connection is established to Calendly’s servers. Technical data (particularly your IP address) is transmitted to Calendly even if you have not booked an appointment. If you book an appointment, the data you enter (name, email address, and any additional information) is also transmitted to Calendly and stored there. Calendly uses this data to coordinate and confirm the appointment.
Embedding the iframe and the associated data transmission on page access is based on Article 6(1)(f) GDPR (legitimate interest in providing a simple appointment booking option). Processing data entered during booking is based on Article 6(1)(b) GDPR (pre-contractual measures). Transfers to the USA are based on the EU-US Data Privacy Framework; Calendly is DPF-certified. We have concluded a data processing agreement with Calendly. Booking data is deleted 6 months after the booked appointment unless a statutory retention obligation requires otherwise. Further information: calendly.com/privacy.
9. Customer Support
9.1. HubSpot (support tickets)
We use HubSpot to handle support inquiries. The provider is HubSpot, Inc., 25 First Street, 2nd Floor, Cambridge, MA 02141, USA.
When you submit a ticket through our support portal (support.b-42.com), the data you enter (name, email address, and the content of your inquiry) is stored in HubSpot and used to address your request. This data is not used for marketing.
Processing is based on Article 6(1)(b) GDPR (performance of a contract or pre-contractual measures) and Article 6(1)(f) GDPR (legitimate interest in efficient support handling). Transfers to the USA are based on the EU-US Data Privacy Framework; HubSpot is DPF-certified. We have concluded a data processing agreement with HubSpot. Further information: legal.hubspot.com/de/privacy-policy.
Support tickets are stored for 3 years after the matter is closed and then deleted (regular statutory limitation period). You can request early deletion of your data at any time by emailing info@b-42.com.
10. User Rights
10.1. Data subject rights
As a data subject, you have the following rights:
- Right of access (Article 15 GDPR): You can request information about the data processed about you.
- Right to rectification (Article 16 GDPR): You can request correction of inaccurate data.
- Right to erasure (Article 17 GDPR): You can request deletion of your data under certain conditions.
- Right to restriction of processing (Article 18 GDPR): You can request restriction of processing of your data.
- Right to data portability (Article 20 GDPR): You can receive your data in a machine-readable format.
- Right to object (Article 21 GDPR): You can object to processing of your data.
The restrictions under sections 34 and 35 of the German Federal Data Protection Act (BDSG) apply to the rights of access and erasure.
10.2. Right to lodge a complaint
You have the right to complain to the competent data protection supervisory authority about our processing of your personal data.
10.3. Withdrawal of consent
You can withdraw consent at any time with effect for the future. Processing carried out before withdrawal is unaffected.
10.4. Objection to direct marketing
Under Article 21(2) GDPR, you have the right to object at any time to processing of your personal data for direct marketing. After your objection, we will no longer process your data for this purpose.
10.5. Links to other websites
Our websites may contain links to other providers’ offerings. This privacy policy applies exclusively to SFY GmbH’s websites. We have no influence over other providers’ privacy practices.
10.6. Changes to this privacy policy
We reserve the right to amend this privacy policy at any time in compliance with applicable data protection regulations. The current version is available on this page.
10.7. Contact
If you have questions about the collection, processing, or use of your personal data, please contact:
SFY GmbH
Industriestraße 15
84149 Velden
Germany
Email: info@b-42.com
App Privacy Policies
B42 App, B42 Nutrition, and CoachZone each have their own product-specific privacy policy: